Buffer Overflow Vulnerability in Huawei Network Products
CVE-2019-5258

5.5MEDIUM

Summary

Huawei's range of network products are affected by a buffer overflow vulnerability that allows an authenticated attacker to exploit message handling weaknesses. By sending specially crafted messages from the internal network port or manipulating inter-process message packets, an attacker can disrupt the normal operation of the affected products. This vulnerability arises due to inadequate validation of incoming messages, potentially leading to unexpected behavior and operational issues within the device.

Affected Version(s)

AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981 V200R005C30

AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981 V200R006C10

AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981 V200R006C20

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.