Out-of-bounds read in multiple Huawei products

Published: 2019-10-24 | Updated: 2019-10-24
Severity Medium
Patch available YES
Number of vulnerabilities 1
CVE ID CVE-2019-5294
CWE ID CWE-125
Exploitation vector Network
Public exploit N/A
Vulnerable software Huawei SRG3300 Subscribe
Huawei SRG2300
Huawei SRG1300
Huawei NetEngine16EX
Huawei AR3600
Huawei AR3200
Huawei AR2200-S
Huawei AR2200
Huawei AR200-S
Huawei AR200
Huawei AR160
Huawei AR150-S
Huawei AR150
Huawei AR1200-S
Huawei AR1200
Huawei AR120-S
Vendor Huawei

Security Advisory

This security advisory describes one medium risk vulnerability.

1) Out-of-bounds read

Severity: Medium

CVSSv3: 4.6 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2019-5294

CWE-ID: CWE-125 - Out-of-bounds Read

Description

The vulnerability allows a remote attacker to cause some abnormal service.

The vulnerability exists due to a boundary condition when parsing a message. A remote attacker can send a specially crafted message, trigger out-of-bounds read error and cause some service abnormal.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Huawei SRG3300: 200R005C20, 200R006C10, 200R007C00

Huawei SRG2300: 200R005C20, 200R006C10, 200R007C00

Huawei SRG1300: 200R005C20, 200R006C10, 200R007C00

Huawei NetEngine16EX: 200R005C20, 200R006C10, 200R007C00

Huawei AR3600: 200R005C20, 200R006C10

Huawei AR3200: 200R005C20, 200R006C10

Huawei AR2200-S: 200R005C20, 200R006C10, 200R007C00

Huawei AR2200: 200R005C20, 200R006C10, 200R007C00

Huawei AR200-S: 200R005C20, 200R006C10, 200R007C00

Huawei AR200: 200R005C20, 200R006C10, 200R007C00

Huawei AR160: 200R005C20, 200R006C10, 200R007C00

Huawei AR150-S: 200R005C20, 200R006C10, 200R007C00

Huawei AR150: 200R005C20, 200R006C10, 200R007C00

Huawei AR1200-S: 200R005C20, 200R006C10, 200R007C00

Huawei AR1200: 200R005C20, 200R006C10, 200R007C00

Huawei AR120-S: 200R005C20, 200R006C10, 200R007C00

CPE External links

https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191023-01-buffer-en

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.