Lucene search

K
cveHuaweiCVE-2019-19414
HistoryJan 21, 2020 - 11:15 p.m.

CVE-2019-19414

2020-01-2123:15:13
CWE-190
huawei
web.nvd.nist.gov
53
cve-2019-19414
huawei
ldap server
integer overflow
remote attacker
input validation
vulnerability
nvd

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

58.8%

There is an integer overflow vulnerability in LDAP server of some Huawei products. Due to insufficient input validation, a remote attacker could exploit this vulnerability by sending malformed packets to the target devices. Successful exploit could cause the affected system crash.

Affected configurations

Nvd
Vulners
Node
huaweidbs3900_tdd_lte_firmwareMatchv100r003c00
OR
huaweidbs3900_tdd_lte_firmwareMatchv100r004c10
AND
huaweidbs3900_tdd_lteMatch-
Node
huaweidp300_firmwareMatchv500r002c00
AND
huaweidp300Match-
Node
huaweirp200_firmwareMatchv500r002c00spc200
OR
huaweirp200_firmwareMatchv600r006c00
AND
huaweirp200Match-
Node
huaweite30_firmwareMatchv100r001c10
OR
huaweite30_firmwareMatchv600r006c00
AND
huaweite30Match-
Node
huaweite40_firmwareMatchv600r006c00
AND
huaweite40Match-
Node
huaweite50_firmwareMatchv600r006c00
AND
huaweite50Match-
Node
huaweite60_firmwareMatchv100r001c10
OR
huaweite60_firmwareMatchv500r002c00
OR
huaweite60_firmwareMatchv600r006c00
AND
huaweite60Match-
VendorProductVersionCPE
huaweidbs3900_tdd_lte_firmwarev100r003c00cpe:2.3:o:huawei:dbs3900_tdd_lte_firmware:v100r003c00:*:*:*:*:*:*:*
huaweidbs3900_tdd_lte_firmwarev100r004c10cpe:2.3:o:huawei:dbs3900_tdd_lte_firmware:v100r004c10:*:*:*:*:*:*:*
huaweidbs3900_tdd_lte-cpe:2.3:h:huawei:dbs3900_tdd_lte:-:*:*:*:*:*:*:*
huaweidp300_firmwarev500r002c00cpe:2.3:o:huawei:dp300_firmware:v500r002c00:*:*:*:*:*:*:*
huaweidp300-cpe:2.3:h:huawei:dp300:-:*:*:*:*:*:*:*
huaweirp200_firmwarev500r002c00spc200cpe:2.3:o:huawei:rp200_firmware:v500r002c00spc200:*:*:*:*:*:*:*
huaweirp200_firmwarev600r006c00cpe:2.3:o:huawei:rp200_firmware:v600r006c00:*:*:*:*:*:*:*
huaweirp200-cpe:2.3:h:huawei:rp200:-:*:*:*:*:*:*:*
huaweite30_firmwarev100r001c10cpe:2.3:o:huawei:te30_firmware:v100r001c10:*:*:*:*:*:*:*
huaweite30_firmwarev600r006c00cpe:2.3:o:huawei:te30_firmware:v600r006c00:*:*:*:*:*:*:*
Rows per page:
1-10 of 191

CNA Affected

[
  {
    "product": "CloudEngine 12800;CloudEngine 5800;CloudEngine 6800;CloudEngine 7800;DBS3900 TDD LTE;DP300;RP200;TE30;TE40;TE50;TE60",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "V100R003C10,V100R005C00,V100R006C00,V200R001C00,V200R002C50"
      },
      {
        "status": "affected",
        "version": "V100R005C00,V100R005C10,V100R006C00,V200R001C00,V200R002C50SPC800"
      },
      {
        "status": "affected",
        "version": "V100R005C00,V100R005C10,V100R006C00,V200R001C00,V200R002C50"
      },
      {
        "status": "affected",
        "version": "V100R005C00,V100R005C10,V200R001C00,V200R002C50"
      },
      {
        "status": "affected",
        "version": "V100R003C00,V100R004C10"
      },
      {
        "status": "affected",
        "version": "V500R002C00"
      },
      {
        "status": "affected",
        "version": "V500R002C00SPC200,V600R006C00"
      },
      {
        "status": "affected",
        "version": "V100R001C10,V600R006C00"
      },
      {
        "status": "affected",
        "version": "V600R006C00"
      },
      {
        "status": "affected",
        "version": "V100R001C10,V500R002C00,V600R006C00"
      },
      {
        "status": "affected",
        "version": "unspecified"
      }
    ]
  }
]

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

58.8%

Related for CVE-2019-19414