Use of a broken or risky cryptographic algorithm in Huawei products - CVE-2019-19397
Published: December 5, 2019
Vulnerability identifier: #VU23420
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19397
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information on the target system.
The vulnerability exists due to the affected products use weak algorithms by default. A remote attacker can exploit this vulnerability to cause information leaks.
Affected software
Huawei S6700
Huawei S9700
Huawei S7700
Huawei S2700
Huawei S1700
Huawei S5700
Huawei S12700
Huawei S9700
Huawei S7700
Huawei S2700
Huawei S1700
Huawei S5700
Huawei S12700
How to mitigate CVE-2019-19397
Install updates from vendor's website.
Huawei S6700 - update to V200R019C00
Huawei S5700 - update to V200R019C00
Huawei S9700 - update to V200R019C00
Huawei S7700 - update to V200R019C00
Huawei S2700 - update to V200R019C00
Huawei S1700 - update to V200R019C00
Huawei S12700 - update to V200R019C00
Huawei S5700 - update to V200R019C00
Huawei S9700 - update to V200R019C00
Huawei S7700 - update to V200R019C00
Huawei S2700 - update to V200R019C00
Huawei S1700 - update to V200R019C00
Huawei S12700 - update to V200R019C00