PT-2019-2033 · Huawei · Srg2300+11

Ivica Stipovic

+1

·

Published

2019-03-20

·

Updated

2019-06-05

·

CVE-2019-5300

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Huawei routers versions AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300, SRG3300
Description The issue is related to a digital signature verification bypass. It occurs because the affected software improperly verifies digital signatures for the software image in the affected device. A local attacker with high privilege may exploit this to bypass integrity checks for software images and install a malicious software image on the affected device.
Recommendations For AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300, SRG3300, consider disabling the software image installation feature until a patch is available to prevent exploitation. Restrict access to the device to minimize the risk of a local attacker with high privilege exploiting the vulnerability. Avoid using the affected devices for critical operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01777
CVE-2019-5300

Affected Products

Ar1200
Ar1200-S
Ar150
Ar160
Ar200
Ar2200
Ar2200-S
Ar3200
Huawei Vrp
Srg1300
Srg2300
Srg3300