CVE-2019-5300
There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers.
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.
- CVSS 3.0
- 6.7 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.19% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347
- Affected
- huawei/ar1200 firmware · huawei/ar1200-s firmware · huawei/ar150 firmware · huawei/ar160 firmware · huawei/ar200 firmware · huawei/ar2200 firmware · huawei/ar2200s firmware · huawei/ar3200 firmware · huawei/srg1300 firmware · huawei/srg2300 firmware · huawei/srg3300 firmware
- Source
- psirt@huawei.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.