7.4
CWE
401
Advisory Published
Updated

CVE-2019-5248

First published: Fri Dec 13 2019(Updated: )

CloudEngine 12800 has a DoS vulnerability. An attacker of a neighboring device sends a large number of specific packets. As a result, a memory leak occurs after the device uses the specific packet. As a result, the attacker can exploit this vulnerability to cause DoS attacks on the target device.

Credit: psirt@huawei.com

Affected SoftwareAffected VersionHow to fix
Huawei CloudEngine 12800=v200r001c00spc600
Huawei CloudEngine 12800=v200r001c00spc700
Huawei CloudEngine 12800=v200r002c01
Huawei CloudEngine 12800=v200r002c50spc800
Huawei CloudEngine 12800=v200r002c50spc800pwe
Huawei CloudEngine 12800

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2019-5248?

    CVE-2019-5248 is classified as a denial-of-service (DoS) vulnerability.

  • How do I fix CVE-2019-5248?

    To fix CVE-2019-5248, update the affected Huawei CloudEngine 12800 firmware to a secure version.

  • What causes the CVE-2019-5248 vulnerability?

    CVE-2019-5248 is caused by a memory leak triggered by a large number of specific packets sent from a neighboring device.

  • Which devices are affected by CVE-2019-5248?

    CVE-2019-5248 affects multiple versions of the Huawei CloudEngine 12800 firmware, including v200r001c00spc600 and v200r002c50spc800.

  • Can CVE-2019-5248 be exploited remotely?

    Yes, CVE-2019-5248 can be exploited remotely by an attacker sending specific packets to the vulnerable device.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203