CVE-2019-5272: Medium severity huawei unified security gateway firmware vulnerability
Published Dec 26, 2019
·Updated
USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected products does not check the integrity which may allow an attacker with high privilege to make malicious modifications without detection.
Affected Software
3 affected components
Huawei Usg9500 Firmware=v500r001c30
Huawei Usg9500 Firmware=v500r001c60
Huawei USG9500
Event History
Dec 26, 2019
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-5272.
2
What is the severity of CVE-2019-5272?
The severity of CVE-2019-5272 is medium with a score of 4.9.
3
Which software versions are affected by CVE-2019-5272?
USG9500 with versions V500R001C30 and V500R001C60 are affected by CVE-2019-5272.
4
What is the impact of the vulnerability?
The vulnerability allows an attacker with high privilege to make malicious modifications without detection.
5
Is there a fix for CVE-2019-5272?
Yes, Huawei has released a security advisory with details on how to fix CVE-2019-5272. Please refer to their official website for more information.