Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board may send crafted messages from the internal network port or tamper with inter-process message packets to exploit this vulnerability. Due to insufficient validation of the message, successful exploit may cause the affected board to be abnormal.

Project Subscriptions

Vendors Products
Ap2000 Firmware Subscribe
Espace U1981 Subscribe
Espace U1981 Firmware Subscribe
Ips Firmware Subscribe
Ngfw Firmware Subscribe
Nip6300 Subscribe
Nip6300 Firmware Subscribe
Nip6600 Subscribe
Nip6600 Firmware Subscribe
Nip6800 Subscribe
Nip6800 Firmware Subscribe
S5700 Firmware Subscribe
Secospace Antiddos8000 Subscribe
Secospace Antiddos8000 Firmware Subscribe
Secospace Usg6300 Subscribe
Secospace Usg6300 Firmware Subscribe
Secospace Usg6500 Subscribe
Secospace Usg6500 Firmware Subscribe
Secospace Usg6600 Subscribe
Secospace Usg6600 Firmware Subscribe
Semg9811 Subscribe
Semg9811 Firmware Subscribe
Svn5600 Subscribe
Svn5600 Firmware Subscribe
Svn5800 Subscribe
Svn5800-c Subscribe
Svn5800-c Firmware Subscribe
Svn5800 Firmware Subscribe
Usg6000v Subscribe
Usg6000v Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-14859 Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board may send crafted messages from the internal network port or tamper with inter-process message packets to exploit this vulnerability. Due to insufficient validation of the message, successful exploit may cause the affected board to be abnormal.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-04T19:47:56.865Z

Reserved: 2019-01-04T00:00:00

Link: CVE-2019-5254

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-13T23:15:11.660

Modified: 2024-11-21T04:44:36.743

Link: CVE-2019-5254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses