There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.

Project Subscriptions

Vendors Products
Ar1200-s Firmware Subscribe
Ar1200 Firmware Subscribe
Ar1200e Subscribe
Ar1220c Subscribe
Ar1220ev Subscribe
Ar1220evw Subscribe
Ar1220f-s Subscribe
Ar150 Firmware Subscribe
Ar158evw Subscribe
Ar160 Firmware Subscribe
Ar161ew Subscribe
Ar161f-dgp Subscribe
Ar161fg-l Subscribe
Ar161fgw-l Subscribe
Ar161fv-1p Subscribe
Ar161fw Subscribe
Ar161g-l Subscribe
Ar168f-4p Subscribe
Ar169egw-l Subscribe
Ar169ew Subscribe
Ar169fgw-l Subscribe
Ar169fvw Subscribe
Ar169fvw-8s Subscribe
Ar169g-l Subscribe
Ar169jfvw-2s Subscribe
Ar200 Firmware Subscribe
Ar2200 Firmware Subscribe
Ar2200s Subscribe
Ar2200s Firmware Subscribe
Ar2204-27ge Subscribe
Ar2204-27ge-p Subscribe
Ar2204-51ge-p Subscribe
Ar2204e Subscribe
Ar2204xe Subscribe
Ar2220e Subscribe
Ar2240c Subscribe
Ar3200 Firmware Subscribe
Srg1300 Firmware Subscribe
Srg1320vw Subscribe
Srg2300 Firmware Subscribe
Srg2320e Subscribe
Srg3300 Firmware Subscribe
Srg3340 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-14905 There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-04T19:54:52.437Z

Reserved: 2019-01-04T00:00:00

Link: CVE-2019-5300

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-04T19:29:00.633

Modified: 2024-11-21T04:44:42.073

Link: CVE-2019-5300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses