First published: Fri Jan 03 2020(Updated: )
Some Huawei products have a buffer error vulnerability. An unauthenticated, remote attacker could send specific MPLS Echo Request messages to the target products. Due to insufficient input validation of some parameters in the messages, successful exploit may cause the device to reset.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei AR120-S | =v200r006c10 | |
Huawei AR120-S | =v200r007c00 | |
Huawei AR120-S | =v200r008c20 | |
Huawei AR120-S | =v200r008c50 | |
Huawei AR120 firmware | ||
Huawei ar1200 firmware | =v200r003c01 | |
Huawei ar1200 firmware | =v200r005c20 | |
Huawei ar1200 firmware | =v200r006c10 | |
Huawei ar1200 firmware | =v200r007c00 | |
Huawei ar1200 firmware | =v200r008c20 | |
Huawei ar1200 firmware | =v200r008c50 | |
Huawei AR1200 | ||
Huawei ar1200-s firmware | =v200r003c01 | |
Huawei ar1200-s firmware | =v200r005c20 | |
Huawei ar1200-s firmware | =v200r006c10 | |
Huawei ar1200-s firmware | =v200r007c00 | |
Huawei ar1200-s firmware | =v200r008c20 | |
Huawei ar1200-s firmware | =v200r008c50 | |
Huawei ar1200-s | ||
Huawei ar150 firmware | =v200r003c01 | |
Huawei ar150 firmware | =v200r005c20 | |
Huawei ar150 firmware | =v200r006c10 | |
Huawei ar150 firmware | =v200r007c00 | |
Huawei ar150 firmware | =v200r008c20 | |
Huawei ar150 firmware | =v200r008c50 | |
Huawei AR 150 | ||
Huawei ar150-s firmware | =v200r003c01 | |
Huawei ar150-s firmware | =v200r005c20 | |
Huawei ar150-s firmware | =v200r006c10 | |
Huawei ar150-s firmware | =v200r007c00 | |
Huawei ar150-s firmware | =v200r008c20 | |
Huawei ar150-s firmware | =v200r008c50 | |
Huawei ar150-s | ||
Huawei AR160 Firmware | =v200r005c20 | |
Huawei AR160 Firmware | =v200r006c10 | |
Huawei AR160 Firmware | =v200r007c00 | |
Huawei AR160 Firmware | =v200r008c20 | |
Huawei AR160 Firmware | =v200r008c50 | |
Huawei AR160 Firmware | ||
Huawei AR200 Firmware | =v200r003c01 | |
Huawei AR200 Firmware | =v200r005c20 | |
Huawei AR200 Firmware | =v200r006c10 | |
Huawei AR200 Firmware | =v200r007c00 | |
Huawei AR200 Firmware | =v200r008c20 | |
Huawei AR200 Firmware | =v200r008c50 | |
Huawei AR200 | ||
Huawei AR200-S Firmware | =v200r003c01 | |
Huawei AR200-S Firmware | =v200r005c20 | |
Huawei AR200-S Firmware | =v200r006c10 | |
Huawei AR200-S Firmware | =v200r007c00 | |
Huawei AR200-S Firmware | =v200r008c20 | |
Huawei AR200-S Firmware | =v200r008c50 | |
Huawei AR200-S Firmware | ||
Huawei AR2200 Series Firmware | =v200r003c01 | |
Huawei AR2200 Series Firmware | =v200r005c20 | |
Huawei AR2200 Series Firmware | =v200r006c10 | |
Huawei AR2200 Series Firmware | =v200r007c00 | |
Huawei AR2200 Series Firmware | =v200r008c20 | |
Huawei AR2200 Series Firmware | =v200r008c50 | |
Huawei AR2200 Series Firmware | ||
Huawei AR2200 Series Firmware | =v200r003c01 | |
Huawei AR2200 Series Firmware | =v200r005c20 | |
Huawei AR2200 Series Firmware | =v200r006c10 | |
Huawei AR2200 Series Firmware | =v200r008c20 | |
Huawei AR2200 Series Firmware | =v200r008c50 | |
Huawei AR2200-S | ||
Huawei AR3200 | =v200r003c01 | |
Huawei AR3200 | =v200r005c20 | |
Huawei AR3200 | =v200r006c10 | |
Huawei AR3200 | =v200r007c00 | |
Huawei AR3200 | =v200r008c20 | |
Huawei AR3200 | =v200r008c50 | |
Huawei AR3200 firmware | ||
Huawei AR3600 Firmware | =v200r006c10 | |
Huawei AR3600 Firmware | =v200r007c00 | |
Huawei AR3600 Firmware | =v200r008c20 | |
Huawei AR3600 Firmware | =v200r008c50 | |
Huawei AR3600 Firmware | ||
Huawei IPS firmware | =v500r001c20 | |
Huawei IPS firmware | =v500r001c30 | |
Huawei IPS Module firmware | ||
Huawei NGFW Module firmware | =v500r001c20 | |
Huawei NGFW Module firmware | =v500r002c00 | |
Huawei NGFW Module | ||
Huawei NIP6300 firmware | =v500r001c20 | |
Huawei NIP6300 firmware | =v500r001c30 | |
Huawei NIP6300 firmware | ||
Huawei NIP6600 | =v500r001c20 | |
Huawei NIP6600 | =v500r001c30 | |
Huawei NIP6600 firmware | ||
Huawei NetEngine 16EX firmware | =v200r005c20 | |
Huawei NetEngine 16EX firmware | =v200r006c10 | |
Huawei NetEngine 16EX firmware | =v200r007c00 | |
Huawei NetEngine 16EX firmware | =v200r008c20 | |
Huawei NetEngine 16EX firmware | =v200r008c50 | |
Huawei NetEngine 16EX | ||
Huawei Campus S5700 firmware | =v200r005c00 | |
Huawei Campus S5700 firmware | =v200r005c02 | |
Huawei Campus S5700 firmware | =v200r005c03 | |
Huawei Campus S5700 firmware | =v200r006c00 | |
Huawei Campus S5700 firmware | =v200r007c00 | |
Huawei Campus S5700 firmware | =v200r008c00 | |
Huawei Campus S5700 firmware | =v200r010c00 | |
Huawei Campus S5700 firmware | =v200r011c00 | |
Huawei S5700 Firmware | ||
Huawei 6700EI firmware | =v200r005c00 | |
Huawei 6700EI firmware | =v200r005c01 | |
Huawei 6700EI firmware | =v200r005c02 | |
Huawei 6700EI firmware | =v200r008c00 | |
Huawei 6700EI firmware | =v200r010c00 | |
Huawei 6700EI firmware | =v200r011c00 | |
Huawei S6700 Firmware | ||
Huawei SRG1300 Firmware | =v200r003c01 | |
Huawei SRG1300 Firmware | =v200r005c20 | |
Huawei SRG1300 Firmware | =v200r006c10 | |
Huawei SRG1300 Firmware | =v200r007c00 | |
Huawei SRG1300 Firmware | =v200r008c20 | |
Huawei SRG1300 Firmware | =v200r008c50 | |
Huawei SRG1300 | ||
Huawei SRG2300 | =v200r003c01 | |
Huawei SRG2300 | =v200r005c20 | |
Huawei SRG2300 | =v200r006c10 | |
Huawei SRG2300 | =v200r007c00 | |
Huawei SRG2300 | =v200r008c20 | |
Huawei SRG2300 | =v200r008c50 | |
Huawei SRG2300 | ||
Huawei SRG3300 | =v200r003c01 | |
Huawei SRG3300 | =v200r005c20 | |
Huawei SRG3300 | =v200r006c10 | |
Huawei SRG3300 | =v200r007c00 | |
Huawei SRG3300 | =v200r008c20 | |
Huawei SRG3300 | =v200r008c50 | |
Huawei SRG3300 | ||
Huawei Secospace AntiDDoS8000 | =v500r001c20 | |
Huawei Secospace AntiDDoS8000 | =v500r001c60 | |
Huawei Secospace AntiDDoS8000 | =v500r005c00 | |
Huawei Secospace AntiDDoS8000 | ||
Huawei USG6300E firmware | =v500r001c20 | |
Huawei USG6300E firmware | =v500r001c30 | |
Huawei Secospace USG6300 firmware | ||
Huawei Secospace USG6500 | =v500r001c20 | |
Huawei Secospace USG6500 | =v500r001c30 | |
Huawei Secospace USG6500 firmware | ||
Huawei Secospace USG6600 firmware | =v500r001c20 | |
Huawei Secospace USG6600 firmware | =v500r001c30 | |
Huawei Secospace USG6600 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5304 has a medium severity rating due to its potential impact on device availability.
To remediate CVE-2019-5304, upgrade your Huawei device firmware to a version that has addressed this vulnerability.
CVE-2019-5304 affects specific versions of Huawei AR120-S, AR1200, AR150, AR160, AR200, AR2200, AR3200, AR3600, and various firmware modules.
Yes, CVE-2019-5304 can be exploited by unauthenticated attackers sending specially crafted MPLS Echo Request messages.
Exploitation of CVE-2019-5304 can lead to the target device resetting, resulting in service disruption.