CVE-2019-19417 - CVE House
Back to Database
Status published High CVE-2019-19417

The SIP module of some Huawei products have a denial...

Vulnerability Description

The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit these three vulnerabilities by sending the specially crafted messages to the affected device. Due to the insufficient verification of the packets, successful exploit could allow the attacker to cause buffer overflow and dead loop, leading to DoS condition. Affected products can be found in https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-01-sip-en.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-19417

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

AR120-S, AR1200, AR1200-S, AR150, AR150-S, AR160, AR200, AR200-S, AR2200, AR2200-S, AR3200, AR3600, AR510, DP300, IPS Module, NGFW Module, NIP6300, NIP6600, NIP6800, NetEngine16EX, RSE6500, SMC2.0, SRG1300, SRG2300, SRG3300, SVN5600, SVN5800, SVN5800-C, SeMG9811, Secospace USG6300, Secospace USG6500, Secospace USG6600, SoftCo, TE30, TE40, TE50, TE60, TP3206, USG9500, USG9520, USG9560, VP9660, ViewPoint 8660, ViewPoint 9030, eSpace U1910, eSpace U1911, eSpace U1930, eSpace U1960, eSpace U1980, eSpace U1981
Vulnerable Versions:
V200R006C10, V200R007C00, V200R008C20 V200R008C30, V200R008C20, V200R008C30, V200R007C01, V200R007C02, V200R006C10SPC300, V200R006C12, V200R006C13, V200R006C16PWE, V200R006C11, V200R008C00, V200R008C10, V200R006C15, V200R006C16, V200R006C17, V200R007C00SPC180T, V200R007C00SPC600, V200R007C00SPC900, V200R007C00SPCb00, V500R002C00, V100R001C10, V100R001C20, V100R001C30, V500R001C00, V500R001C20, V500R001C30, V500R001C50, V500R002C10, V100R003C00SPC200T, V100R003C00SPC300T, V100R003C00SPC301T, V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SPC102, V100R005C00SPC103, V100R005C00SPC200, V100R005C00SPC201T, V600R006C00, V200R003C00, V200R003C10, V300R001C01SPC500, V300R001C01SPC500T, V300R001C01SPC700, V300R001C01SPCa00, V100R001C00, V200R001C01SPC300, V200R001C01SPC400, V200R001C01SPC500, V200R001C01SPC600, V200R001C01SPH703, V200R003C00SPC100, V200R003C00SPC200, V200R003C00SPC300, V200R003C00SPC500, V200R003C20, V100R001C02SPC100, V100R001C02SPC200 V100R001C10, V500R002C00SPC200, V500R002C00SPC600, V500R002C00SPC700, V500R002C00SPC900, V500R002C00SPCb00, V100R001C01SPC100, V100R001C10SPC300, V100R001C10SPC400, V100R001C10SPC500, V100R001C10SPC600, V100R001C10SPC800, V100R003C00, V500R002C00SPC100, V500R002C00SPC300, V500R002C00SPC800, V500R002C00SPCa00, V600R006C00SPC200, V100R002C00, V300R001C01, V300R001C20, V300R001C01SPC800PWE, V300R001C20SPC300, V200R001C02SPC100, V200R001C02SPC200, V200R001C02SPC300, V200R001C02SPC300T, V200R001C02SPC400, V200R001C30SPC100, V200R001C30SPC100B015T, V200R001C30SPC101, V200R001C30SPC101TB015, V200R001C30SPC102T, V200R001C30SPC103T, V200R001C30SPC104T, V200R001C30SPC200, V200R001C30SPC200B022T, V200R001C30SPC201B023T, V200R001C30SPC202B025T, V200R001C30SPC203T, V200R001C30SPC206T, V200R001C30SPC207T, V200R001C30SPC208T, V200R001C30SPC209T, V200R001C30SPC300, V200R001C30SPC400, V200R001C30SPC400B001, V200R001C30SPC400T, V200R001C30SPC401T, V200R001C30SPC402T, V200R001C30SPC403T, V200R001C30SPC404T, V200R001C30SPC405T, V200R001C30SPC600, V200R001C30SPC700, V200R001C30SPC700T, V200R001C30SPC701T, V200R001C30SPC702T, V200R001C30SPC703T, V200R001C30SPC800, V200R001C30SPC800T, V200R001C30SPC900, V200R001C30SPCa00, V200R001C30SPCa00T, V200R001C30SPCa01, V200R001C30SPCa01T, V200R001C30SPCa02T, V200R001C30SPCb00, V200R001C30SPCc00, V200R001C30SPCd00, V200R001C30SPCd00T, V200R001C30SPCd01T, V200R001C30SPCd, V100R008C03B013SP02, V100R008C03B013SP03, V100R008C03B013SP04, V100R008C03SPC100, V100R008C03SPC200, V100R008C03SPC300, V100R008C03SPC400, V100R008C03SPC500, V100R008C03SPC600, V100R008C03SPC700, V100R008C03SPC800, V100R008C03SPC900, V100R008C03SPCa00, V100R008C03SPCb00, V100R008C03SPCc00, V100R011C02SPC100, V100R011C03B012SP15, V100R011C03B012SP16, V100R011C03B015SP03, V100R011C03LGWL01SPC100, V100R011C03LGWL01SPC100B012, V100R011C03SPC100, V100R011C03SPC200, V100R011C03SPC300, V100R011C03SPC400, V100R011C03SPC500, V100R001C20SPC300, V100R001C20SPC400, V100R001C20SPC500, V100R001C20SPC600, V100R001C20SPH703, V200R003C30, V100R001C20SPH309, V100R001C01SPC500, V100R001C20LCRW01T, V100R001C20SPC600T, V100R001C01SPC500T, V100R001C20SPC500T, V100R001C20SPC502, V100R001C20SPC700, V100R001C20SPH702

Timeline

Official Publish: July 8th, 2020
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.