PT-2019-2033 · Huawei · Srg2300+11
Ivica Stipovic
+1
·
Published
2019-03-20
·
Updated
2019-06-05
·
CVE-2019-5300
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Huawei routers versions AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300, SRG3300
Description
The issue is related to a digital signature verification bypass. It occurs because the affected software improperly verifies digital signatures for the software image in the affected device. A local attacker with high privilege may exploit this to bypass integrity checks for software images and install a malicious software image on the affected device.
Recommendations
For AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300, SRG3300, consider disabling the software image installation feature until a patch is available to prevent exploitation.
Restrict access to the device to minimize the risk of a local attacker with high privilege exploiting the vulnerability.
Avoid using the affected devices for critical operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ar1200
Ar1200-S
Ar150
Ar160
Ar200
Ar2200
Ar2200-S
Ar3200
Huawei Vrp
Srg1300
Srg2300
Srg3300