Vulnerability Description
There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Ar1200 Firmware | v200r007c00 |
| Huawei | Ar1200E | - |
| Huawei | Ar1220C | - |
| Huawei | Ar1220Ev | - |
| Huawei | Ar1220Evw | - |
| Huawei | Ar1200-S Firmware | v200r007c00 |
| Huawei | Ar1220F-S | - |
| Huawei | Ar150 Firmware | v200r007c00 |
| Huawei | Ar158Evw | - |
| Huawei | Ar160 Firmware | v200r007c00 |
| Huawei | Ar161 | - |
| Huawei | Ar161Ew | - |
| Huawei | Ar161F | - |
| Huawei | Ar161F-Dgp | - |
| Huawei | Ar161Fg-L | - |
| Huawei | Ar161Fgw-L | - |
| Huawei | Ar161Fv-1P | - |
| Huawei | Ar161Fw | - |
| Huawei | Ar161G-L | - |
| Huawei | Ar161W | - |
Related Weaknesses (CWE)
References
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190320-01-ar-enVendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190320-01-ar-enVendor Advisory
FAQ
What is CVE-2019-5300?
CVE-2019-5300 is a vulnerability with a CVSS score of 6.7 (MEDIUM). There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due...
How severe is CVE-2019-5300?
CVE-2019-5300 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5300?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Ar1200 Firmware, Huawei Ar1200E, Huawei Ar1220C, Huawei Ar1220Ev, Huawei Ar1220Evw.