Improper authentication in Huawei E5572-855



Published: 2019-12-05
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2019-5253
CWE-ID CWE-287
Exploitation vector Local network
Public exploit N/A
Vulnerable software
Subscribe
Huawei E5572-855
Hardware solutions / Routers for home users

Vendor Huawei

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Improper Authentication

EUVDB-ID: #VU23417

Risk: Low

CVSSv3.1: 4.6 [CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-5253

CWE-ID: CWE-287 - Improper Authentication

Exploit availability: No

Description

The vulnerability allows a local attacker to bypass authentication process.

The vulnerability exists due to the affected device does not perform a sufficient authentication when doing certain operation. A remote attacker on the local network can perform a man-in-the-middle attack and cause a denial of service (DoS) condition on the target system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Huawei E5572-855: before 8.0.1.3

External links

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191204-04-dos-en


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###