Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Huawei
Subscribe
|
Ar120-s
Subscribe
Ar120-s Firmware
Subscribe
Ar1200
Subscribe
Ar1200-s
Subscribe
Ar1200-s Firmware
Subscribe
Ar1200 Firmware
Subscribe
Ar150
Subscribe
Ar150-s
Subscribe
Ar150-s Firmware
Subscribe
Ar150 Firmware
Subscribe
Ar160
Subscribe
Ar160 Firmware
Subscribe
Ar200
Subscribe
Ar200-s
Subscribe
Ar200-s Firmware
Subscribe
Ar200 Firmware
Subscribe
Ar2200
Subscribe
Ar2200-s
Subscribe
Ar2200-s Firmware
Subscribe
Ar2200 Firmware
Subscribe
Ar3200
Subscribe
Ar3200 Firmware
Subscribe
Ar3600
Subscribe
Ar3600 Firmware
Subscribe
Cloudengine 12800
Subscribe
Cloudengine 12800 Firmware
Subscribe
Netengine16ex
Subscribe
Netengine16ex Firmware
Subscribe
S6700
Subscribe
S6700 Firmware
Subscribe
Srg1300
Subscribe
Srg1300 Firmware
Subscribe
Srg2300
Subscribe
Srg2300 Firmware
Subscribe
Srg3300
Subscribe
Srg3300 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-14896 | Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-08-04T19:54:52.966Z
Reserved: 2019-01-04T00:00:00
Link: CVE-2019-5291
No data.
Status : Modified
Published: 2019-12-13T15:15:11.457
Modified: 2024-11-21T04:44:41.010
Link: CVE-2019-5291
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD