Vulnerability Description
USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in a large heap buffer overrun error, an attacker may exploit the vulnerability by a malicious certificate, resulting a denial of service on the affected products.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Usg9500 Firmware | v500r001c30 |
| Huawei | Usg9500 | - |
Related Weaknesses (CWE)
References
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191225-01-eudemoVendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191225-01-eudemoVendor Advisory
FAQ
What is CVE-2019-5273?
CVE-2019-5273 is a vulnerability with a CVSS score of 7.5 (HIGH). USG9500 with versions of V500R001C30;V500R001C60 have a denial of service vulnerability. Due to a flaw in the X.509 implementation in the affected products which can result in a large heap buffer over...
How severe is CVE-2019-5273?
CVE-2019-5273 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5273?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Usg9500 Firmware, Huawei Usg9500.