Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-5272


USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected products does not check the integrity which may allow an attacker with high privilege to make malicious modifications without detection.


Published

2019-12-26T19:15:10.920

Last Modified

2024-11-21T04:44:38.910

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-354

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei usg9500_firmware v500r001c30 Yes
Operating System huawei usg9500_firmware v500r001c60 Yes
Hardware huawei usg9500 - No

References