CVE-2019-5291: Medium severity huawei ar120 firmware vulnerability
Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device to be abnormal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5291?
The severity of CVE-2019-5291 is significant as it allows remote, unauthenticated attackers to manipulate data packets.
How do I fix CVE-2019-5291?
To fix CVE-2019-5291, it is recommended to upgrade to the latest firmware versions provided by Huawei.
Which devices are affected by CVE-2019-5291?
Affected devices include various versions of Huawei AR1200, AR150, AR200, AR2200, AR3200, and others listed in the CVE.
What type of vulnerability is CVE-2019-5291?
CVE-2019-5291 is a data authenticity vulnerability that results from insufficient packet verification.
Can CVE-2019-5291 be exploited without authentication?
Yes, CVE-2019-5291 can be exploited by remote attackers without any authentication.