#VU23627 NULL pointer dereference in Huawei products - CVE-2019-5256
Published: December 17, 2019
Vulnerability identifier: #VU23627
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-5256
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Huawei AP2000
Huawei IPS Module
Huawei NIP6300
Huawei NIP6600
Huawei NIP6800
Huawei Secospace AntiDDoS8000
Huawei NGFW Module
Huawei SVN5600
Huawei SVN5800
Huawei SVN5800-C
Huawei S5700
Huawei SeMG9811
Huawei Secospace USG6300
Huawei Secospace USG6500
Huawei Secospace USG6600
Huawei USG6000V
Huawei eSpace U1981
Huawei AP2000
Huawei IPS Module
Huawei NIP6300
Huawei NIP6600
Huawei NIP6800
Huawei Secospace AntiDDoS8000
Huawei NGFW Module
Huawei SVN5600
Huawei SVN5800
Huawei SVN5800-C
Huawei S5700
Huawei SeMG9811
Huawei Secospace USG6300
Huawei Secospace USG6500
Huawei Secospace USG6600
Huawei USG6000V
Huawei eSpace U1981
Software vendor:
Huawei
Huawei
Description
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A local attacker can send specially crafted parameters, cause a denial of service condition and the process reboot.
Remediation
Install updates from vendor's website.