CVE-2019-5300
There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.
Published:Jun 4, 2019
Last Modified:Nov 21, 2024
EPS:Jun 4, 2019
EPSS Score:0.00011
CVSS Score:6.7
Affected Products
Vendor
Product
Action
Vendor
Huawei
Product
Ar1200-s Firmware
Huawei
Ar1200-s Firmware
Vendor
Huawei
Product
Ar1200 Firmware
Huawei
Ar1200 Firmware
Vendor
Huawei
Product
Ar1200e
Huawei
Ar1200e
Vendor
Huawei
Product
Ar1220c
Huawei
Ar1220c
Vendor
Huawei
Product
Ar1220ev
Huawei
Ar1220ev
Vendor
Huawei
Product
Ar1220evw
Huawei
Ar1220evw
Vendor
Huawei
Product
Ar1220f-s
Huawei
Ar1220f-s
Vendor
Huawei
Product
Ar150 Firmware
Huawei
Ar150 Firmware
Vendor
Huawei
Product
Ar158evw
Huawei
Ar158evw
Vendor
Huawei
Product
Ar160 Firmware
Huawei
Ar160 Firmware
Vendor
Huawei
Product
Ar161
Huawei
Ar161
Vendor
Huawei
Product
Ar161ew
Huawei
Ar161ew
Vendor
Huawei
Product
Ar161f
Huawei
Ar161f
Vendor
Huawei
Product
Ar161f-dgp
Huawei
Ar161f-dgp
Vendor
Huawei
Product
Ar161fg-l
Huawei
Ar161fg-l
Vendor
Huawei
Product
Ar161fgw-l
Huawei
Ar161fgw-l
Vendor
Huawei
Product
Ar161fv-1p
Huawei
Ar161fv-1p
Vendor
Huawei
Product
Ar161fw
Huawei
Ar161fw
Vendor
Huawei
Product
Ar161g-l
Huawei
Ar161g-l
Vendor
Huawei
Product
Ar161w
Huawei
Ar161w
Vendor
Huawei
Product
Ar168f
Huawei
Ar168f
Vendor
Huawei
Product
Ar168f-4p
Huawei
Ar168f-4p
Vendor
Huawei
Product
Ar169
Huawei
Ar169
Vendor
Huawei
Product
Ar169egw-l
Huawei
Ar169egw-l
Vendor
Huawei
Product
Ar169ew
Huawei
Ar169ew
Vendor
Huawei
Product
Ar169f
Huawei
Ar169f
Vendor
Huawei
Product
Ar169fgw-l
Huawei
Ar169fgw-l
Vendor
Huawei
Product
Ar169fvw
Huawei
Ar169fvw
Vendor
Huawei
Product
Ar169fvw-8s
Huawei
Ar169fvw-8s
Vendor
Huawei
Product
Ar169g-l
Huawei
Ar169g-l
Vendor
Huawei
Product
Ar169jfvw-2s
Huawei
Ar169jfvw-2s
Vendor
Huawei
Product
Ar169w
Huawei
Ar169w
Vendor
Huawei
Product
Ar200 Firmware
Huawei
Ar200 Firmware
Vendor
Huawei
Product
Ar201
Huawei
Ar201
Vendor
Huawei
Product
Ar2200 Firmware
Huawei
Ar2200 Firmware
Vendor
Huawei
Product
Ar2200s
Huawei
Ar2200s
Vendor
Huawei
Product
Ar2200s Firmware
Huawei
Ar2200s Firmware
Vendor
Huawei
Product
Ar2204-27ge
Huawei
Ar2204-27ge
Vendor
Huawei
Product
Ar2204-27ge-p
Huawei
Ar2204-27ge-p
Vendor
Huawei
Product
Ar2204-51ge-p
Huawei
Ar2204-51ge-p
Vendor
Huawei
Product
Ar2204e
Huawei
Ar2204e
Vendor
Huawei
Product
Ar2204xe
Huawei
Ar2204xe
Vendor
Huawei
Product
Ar2220e
Huawei
Ar2220e
Vendor
Huawei
Product
Ar2240
Huawei
Ar2240
Vendor
Huawei
Product
Ar2240c
Huawei
Ar2240c
Vendor
Huawei
Product
Ar3200 Firmware
Huawei
Ar3200 Firmware
Vendor
Huawei
Product
Ar3260
Huawei
Ar3260
Vendor
Huawei
Product
Srg1300 Firmware
Huawei
Srg1300 Firmware
Vendor
Huawei
Product
Srg1320vw
Huawei
Srg1320vw
Vendor
Huawei
Product
Srg2300 Firmware
Huawei
Srg2300 Firmware
Vendor
Huawei
Product
Srg2320e
Huawei
Srg2320e
Vendor
Huawei
Product
Srg3300 Firmware
Huawei
Srg3300 Firmware
Vendor
Huawei
Product
Srg3340
Huawei
Srg3340
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
