Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU22276
Risk: Medium
CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2019-5294
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
Description
The vulnerability allows a remote attacker to cause some abnormal service.
The vulnerability exists due to a boundary condition when parsing a message. A remote attacker can send a specially crafted message, trigger out-of-bounds read error and cause some service abnormal.
Install updates from vendor's website.
Vulnerable software versionsHuawei SRG3300: V200R005C20 - V200R007C00
Huawei SRG2300: V200R005C20 - V200R007C00
Huawei SRG1300: V200R005C20 - V200R007C00
Huawei NetEngine16EX: V200R005C20 - V200R007C00
Huawei AR3600: V200R005C20 - V200R006C10
Huawei AR3200: V200R005C20 - V200R006C10
Huawei AR2200-S: V200R005C20 - V200R007C00
Huawei AR2200: V200R005C20 - V200R007C00
Huawei AR200-S: V200R005C20 - V200R007C00
Huawei AR200: V200R005C20 - V200R007C00
Huawei AR160: V200R005C20 - V200R007C00
Huawei AR150-S: V200R005C20 - V200R007C00
Huawei AR150: V200R005C20 - V200R007C00
Huawei AR1200-S: V200R005C20 - V200R007C00
Huawei AR1200: V200R005C20 - V200R007C00
Huawei AR120-S: V200R005C20 - V200R007C00
External linkshttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191023-01-buffer-en
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.