First published: Thu Dec 26 2019(Updated: )
USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the affected products does not check the integrity which may allow an attacker with high privilege to make malicious modifications without detection.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Usg9500 Firmware | =v500r001c30 | |
Huawei Usg9500 Firmware | =v500r001c60 | |
Huawei USG9500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-5272.
The severity of CVE-2019-5272 is medium with a score of 4.9.
USG9500 with versions V500R001C30 and V500R001C60 are affected by CVE-2019-5272.
The vulnerability allows an attacker with high privilege to make malicious modifications without detection.
Yes, Huawei has released a security advisory with details on how to fix CVE-2019-5272. Please refer to their official website for more information.