Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-5294


There is an out of bound read vulnerability in some Huawei products. A remote, unauthenticated attacker may send a corrupt or crafted message to the affected products. Due to a buffer read overflow error when parsing the message, successful exploit may cause some service to be abnormal.


Published

2019-11-13T17:15:14.133

Last Modified

2024-11-21T04:44:41.387

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei ar120-s_firmware v200r005c20 Yes
Operating System huawei ar120-s_firmware v200r006c10 Yes
Operating System huawei ar120-s_firmware v200r007c00 Yes
Hardware huawei ar120-s - No
Operating System huawei ar1200_firmware v200r005c20 Yes
Operating System huawei ar1200_firmware v200r006c10 Yes
Operating System huawei ar1200_firmware v200r007c00 Yes
Hardware huawei ar1200 - No
Operating System huawei ar1200-s_firmware v200r005c20 Yes
Operating System huawei ar1200-s_firmware v200r006c10 Yes
Operating System huawei ar1200-s_firmware v200r007c00 Yes
Hardware huawei ar1200-s - No
Operating System huawei ar150_firmware v200r005c20 Yes
Operating System huawei ar150_firmware v200r006c10 Yes
Operating System huawei ar150_firmware v200r007c00 Yes
Hardware huawei ar150 - No
Operating System huawei ar150-s_firmware v200r005c20 Yes
Operating System huawei ar150-s_firmware v200r006c10 Yes
Operating System huawei ar150-s_firmware v200r007c00 Yes
Hardware huawei ar150-s - No
Operating System huawei ar160_firmware v200r005c20 Yes
Operating System huawei ar160_firmware v200r006c10 Yes
Operating System huawei ar160_firmware v200r007c00 Yes
Hardware huawei ar160 - No
Operating System huawei ar200_firmware v200r005c20 Yes
Operating System huawei ar200_firmware v200r006c10 Yes
Operating System huawei ar200_firmware v200r007c00 Yes
Hardware huawei ar200 - No
Operating System huawei ar200-s_firmware v200r005c20 Yes
Operating System huawei ar200-s_firmware v200r006c10 Yes
Operating System huawei ar200-s_firmware v200r007c00 Yes
Hardware huawei ar200-s - No
Operating System huawei ar2200_firmware v200r005c20 Yes
Operating System huawei ar2200_firmware v200r006c10 Yes
Operating System huawei ar2200_firmware v200r007c00 Yes
Hardware huawei ar2200 - No
Operating System huawei ar2200-s_firmware v200r005c20 Yes
Operating System huawei ar2200-s_firmware v200r006c10 Yes
Operating System huawei ar2200-s_firmware v200r007c00 Yes
Hardware huawei ar2200-s - No
Operating System huawei ar3200_firmware v200r005c20 Yes
Operating System huawei ar3200_firmware v200r006c10 Yes
Hardware huawei ar3200 - No
Operating System huawei ar3600_firmware v200r006c10 Yes
Operating System huawei ar3600_firmware v200r007c00 Yes
Hardware huawei ar3600 - No
Operating System huawei netengine16ex_firmware v200r005c20 Yes
Operating System huawei netengine16ex_firmware v200r006c10 Yes
Operating System huawei netengine16ex_firmware v200r007c00 Yes
Hardware huawei netengine16ex - No
Operating System huawei srg1300_firmware v200r005c20 Yes
Operating System huawei srg1300_firmware v200r006c10 Yes
Operating System huawei srg1300_firmware v200r007c00 Yes
Hardware huawei srg1300 - No
Operating System huawei srg2300_firmware v200r005c20 Yes
Operating System huawei srg2300_firmware v200r006c10 Yes
Operating System huawei srg2300_firmware v200r007c00 Yes
Hardware huawei srg2300 - No
Operating System huawei srg3300_firmware v200r005c20 Yes
Operating System huawei srg3300_firmware v200r006c10 Yes
Operating System huawei srg3300_firmware v200r007c00 Yes
Hardware huawei srg3300 - No

References