Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.

Project Subscriptions

Vendors Products
Ar120-s Subscribe
Ar120-s Firmware Subscribe
Ar1200-s Subscribe
Ar1200-s Firmware Subscribe
Ar1200 Firmware Subscribe
Ar150-s Subscribe
Ar150-s Firmware Subscribe
Ar150 Firmware Subscribe
Ar160 Firmware Subscribe
Ar200-s Subscribe
Ar200-s Firmware Subscribe
Ar200 Firmware Subscribe
Ar2200-s Subscribe
Ar2200-s Firmware Subscribe
Ar2200 Firmware Subscribe
Ar3200 Firmware Subscribe
Ar3600 Firmware Subscribe
Cloudengine 12800 Subscribe
Cloudengine 12800 Firmware Subscribe
Netengine16ex Subscribe
Netengine16ex Firmware Subscribe
S6700 Firmware Subscribe
Srg1300 Subscribe
Srg1300 Firmware Subscribe
Srg2300 Subscribe
Srg2300 Firmware Subscribe
Srg3300 Subscribe
Srg3300 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-14896 Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-04T19:54:52.966Z

Reserved: 2019-01-04T00:00:00

Link: CVE-2019-5291

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-13T15:15:11.457

Modified: 2024-11-21T04:44:41.010

Link: CVE-2019-5291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses