There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-14905 There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-04T19:54:52.437Z

Reserved: 2019-01-04T00:00:00

Link: CVE-2019-5300

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-04T19:29:00.633

Modified: 2024-11-21T04:44:42.073

Link: CVE-2019-5300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses