SB2019072905 - Improper certifiacte verification in Huawei 7900 IP Phones



SB2019072905 - Improper certifiacte verification in Huawei 7900 IP Phones

Published: July 29, 2019

Security Bulletin ID SB2019072905
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Certificate Validation (CVE-ID: CVE-2019-5280)

The vulnerability allows a remote attacker to cause affected phones registered abnormally.

The vulnerability exists due to the insufficient verification of specific parameters of the TLS server certificate. A remote attacker can perform man-in-the-middle attacks. This leads to the affected phones registered abnormally, affects the availability of IP phones.



Remediation

Install update from vendor's website.