Description
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board may send crafted messages from the internal network port or tamper with inter-process message packets to exploit this vulnerability. Due to insufficient validation of the message, successful exploit may cause the affected board to be abnormal.
Published: 2019-12-13
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-14859 Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board may send crafted messages from the internal network port or tamper with inter-process message packets to exploit this vulnerability. Due to insufficient validation of the message, successful exploit may cause the affected board to be abnormal.
History

No history.

Subscriptions

Huawei Ap2000 Ap2000 Firmware Espace U1981 Espace U1981 Firmware Ips Ips Firmware Ngfw Ngfw Firmware Nip6300 Nip6300 Firmware Nip6600 Nip6600 Firmware Nip6800 Nip6800 Firmware S5700 S5700 Firmware Secospace Antiddos8000 Secospace Antiddos8000 Firmware Secospace Usg6300 Secospace Usg6300 Firmware Secospace Usg6500 Secospace Usg6500 Firmware Secospace Usg6600 Secospace Usg6600 Firmware Semg9811 Semg9811 Firmware Svn5600 Svn5600 Firmware Svn5800 Svn5800-c Svn5800-c Firmware Svn5800 Firmware Usg6000v Usg6000v Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-04T19:47:56.865Z

Reserved: 2019-01-04T00:00:00.000Z

Link: CVE-2019-5254

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-13T23:15:11.660

Modified: 2024-11-21T04:44:36.743

Link: CVE-2019-5254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses