MEDIUM · 5.5

CVE-2019-5256

Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG...

Vulnerability Description

Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have a null pointer dereference vulnerability. The system dereferences a pointer that it expects to be valid, but is NULL. A local attacker could exploit this vulnerability by sending crafted parameters. A successful exploit could cause a denial of service and the process reboot.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
HuaweiAp2000 Firmwarev200r005c30
HuaweiAp2000-
HuaweiIps Firmwarev500r001c00spc300
HuaweiIps-
HuaweiNgfw Firmwarev500r001c00spc300
HuaweiNgfw-
HuaweiNip6300 Firmwarev500r001c00spc300
HuaweiNip6300-
HuaweiNip6600 Firmwarev500r001c00spc300
HuaweiNip6600-
HuaweiNip6800 Firmwarev500r001c50
HuaweiNip6800-
HuaweiS5700 Firmwarev200r005c03
HuaweiS5700-
HuaweiSvn5600 Firmwarev200r003c00spc100
HuaweiSvn5600-
HuaweiSvn5800 Firmwarev200r003c00spc100
HuaweiSvn5800-
HuaweiSvn5800-C Firmwarev200r003c00spc100
HuaweiSvn5800-C-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-5256?

CVE-2019-5256 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG...

How severe is CVE-2019-5256?

CVE-2019-5256 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-5256?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Ap2000 Firmware, Huawei Ap2000, Huawei Ips Firmware, Huawei Ips, Huawei Ngfw Firmware.