SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-5300

There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers.

MEDIUM 6.7EPSS 0.19%

Does this matter?

Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.

Description

There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.

CVSS 3.0
6.7 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.19% probability · 8th percentile
CISA KEV
Not listed
Weakness
CWE-347
Affected
huawei/ar1200 firmware · huawei/ar1200-s firmware · huawei/ar150 firmware · huawei/ar160 firmware · huawei/ar200 firmware · huawei/ar2200 firmware · huawei/ar2200s firmware · huawei/ar3200 firmware · huawei/srg1300 firmware · huawei/srg2300 firmware · huawei/srg3300 firmware
Source
psirt@huawei.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.