Vulnerability Description
The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Ar120-S Firmware | v200r006c10 |
| Huawei | Ar120-S | - |
| Huawei | Ar1200 Firmware | v200r006c10 |
| Huawei | Ar1200 | - |
| Huawei | Ar1200-S Firmware | v200r006c10 |
| Huawei | Ar1200-S | - |
| Huawei | Ar150 Firmware | v200r006c10 |
| Huawei | Ar150 | - |
| Huawei | Ar150-S Firmware | v200r006c10spc300 |
| Huawei | Ar150-S | - |
| Huawei | Ar160 Firmware | v200r006c10 |
| Huawei | Ar160 | - |
| Huawei | Ar200 Firmware | v200r006c10 |
| Huawei | Ar200 | - |
| Huawei | Ar200-S Firmware | v200r006c10 |
| Huawei | Ar200-S | - |
| Huawei | Ar2200 Firmware | v200r006c10 |
| Huawei | Ar2200 | - |
| Huawei | Ar2200-S Firmware | v200r006c10 |
| Huawei | Ar2200-S | - |
Related Weaknesses (CWE)
References
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-enVendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-enVendor Advisory
FAQ
What is CVE-2019-19417?
CVE-2019-19417 is a vulnerability with a CVSS score of 7.5 (HIGH). The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affect...
How severe is CVE-2019-19417?
CVE-2019-19417 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19417?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Ar120-S Firmware, Huawei Ar120-S, Huawei Ar1200 Firmware, Huawei Ar1200, Huawei Ar1200-S Firmware.