First published: Wed Nov 13 2019(Updated: )
Some Huawei products have a memory leak vulnerability when handling some messages. A remote attacker with operation privilege could exploit the vulnerability by sending specific messages continuously. Successful exploit may cause some service to be abnormal.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Ar120-s Firmware | =v200r005c20 | |
Huawei Ar120-s Firmware | =v200r006c10 | |
Huawei AR120-S | ||
Huawei Ar1200 Firmware | =v200r005c20 | |
Huawei Ar1200 Firmware | =v200r006c10 | |
Huawei AR1200 | ||
Huawei Ar1200-s Firmware | =v200r005c20 | |
Huawei Ar1200-s Firmware | =v200r006c10 | |
Huawei Ar1200-s | ||
Huawei Ar150 Firmware | =v200r005c20 | |
Huawei Ar150 Firmware | =v200r006c10 | |
Huawei Ar150 | ||
Huawei Ar150-s Firmware | =v200r005c20 | |
Huawei Ar150-s Firmware | =v200r006c10 | |
Huawei Ar150-s | ||
Huawei Ar160 Firmware | =v200r005c20 | |
Huawei Ar160 Firmware | =v200r006c10 | |
Huawei Ar160 | ||
Huawei Ar200 Firmware | =v200r005c20 | |
Huawei Ar200 Firmware | =v200r006c10 | |
Huawei Ar200 | ||
Huawei Ar200-s Firmware | =v200r005c20 | |
Huawei Ar200-s Firmware | =v200r006c10 | |
Huawei Ar200-s | ||
Huawei Ar2200 Firmware | =v200r005c20 | |
Huawei Ar2200 Firmware | =v200r006c10 | |
Huawei Ar2200 | ||
Huawei Ar2200-s Firmware | =v200r005c20 | |
Huawei Ar2200-s Firmware | =v200r006c10 | |
Huawei Ar2200-s | ||
Huawei Ar3200 Firmware | =v200r005c20 | |
Huawei Ar3200 Firmware | =v200r006c10 | |
Huawei AR3200 | ||
Huawei Ar3600 Firmware | =v200r006c10 | |
Huawei Ar3600 | ||
Huawei Netengine16ex Firmware | =v200r005c20 | |
Huawei Netengine16ex Firmware | =v200r006c10 | |
Huawei Netengine16ex | ||
Huawei Srg1300 Firmware | =v200r005c20 | |
Huawei Srg1300 Firmware | =v200r006c10 | |
Huawei Srg1300 | ||
Huawei Srg2300 Firmware | =v200r005c20 | |
Huawei Srg2300 Firmware | =v200r006c10 | |
Huawei Srg2300 | ||
Huawei Srg3300 Firmware | =v200r005c20 | |
Huawei Srg3300 Firmware | =v200r006c10 | |
Huawei Srg3300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-5293.
The severity of CVE-2019-5293 is medium (6.5).
Some Huawei products affected by CVE-2019-5293 include Ar120-s Firmware, Ar1200 Firmware, Ar160 Firmware, Ar200 Firmware, Ar2200 Firmware, Ar3200 Firmware, Ar3600 Firmware, Netengine16ex Firmware, Srg1300 Firmware, Srg2300 Firmware, and Srg3300 Firmware.
The vulnerability in CVE-2019-5293 is a memory leak vulnerability that can be exploited by a remote attacker with operation privilege by sending specific messages continuously, leading to abnormal service behavior.
To mitigate the vulnerability, it is recommended to upgrade to the specified firmware versions provided by Huawei. Please refer to the vendor's security advisory for more information.