Use of a broken or risky cryptographic algorithm in Huawei products - CVE-2019-19397
Published: December 5, 2019
Vulnerability identifier: #VU23420
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-19397
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Huawei
Affected software:
Huawei S12700
Huawei S5700
Huawei S1700
Huawei S2700
Huawei S6700
Huawei S7700
Huawei S9700
Huawei S12700
Huawei S5700
Huawei S1700
Huawei S2700
Huawei S6700
Huawei S7700
Huawei S9700
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to sensitive information on the target system.
The vulnerability exists due to the affected products use weak algorithms by default. A remote attacker can exploit this vulnerability to cause information leaks.
How to mitigate CVE-2019-19397
Install updates from vendor's website.