CVE-2019-5254 - CVE House
Back to Database
Status published High CVE-2019-5254

Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace...

Vulnerability Description

Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board may send crafted messages from the internal network port or tamper with inter-process message packets to exploit this vulnerability. Due to insufficient validation of the message, successful exploit may cause the affected board to be abnormal.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-5254

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981
Vulnerable Versions:
V200R005C30, V200R006C10, V200R006C20, V200R007C10, V200R007C20, V200R008C00, V200R008C10, V200R009C00, V500R001C00SPC300, V500R001C00SPC500, V500R001C00SPH303, V500R001C00SPH508, V500R001C20, V500R001C20SPC100, V500R001C20SPC100PWE, V500R001C20SPC200, V500R001C20SPC200B062, V500R001C20SPC200PWE, V500R001C20SPC300B078, V500R001C20SPC300PWE, V500R001C30, V500R001C30SPC100, V500R001C30SPC100PWE, V500R001C30SPC200, V500R001C30SPC200PWE, V500R001C30SPC300, V500R001C50, V500R001C50PWE, V500R001C80, V500R005C00, V500R001C00SPC500PWE, V500R002C00, V500R002C00SPC100, V500R002C00SPC100PWE, V500R002C00SPC200, V500R002C00SPC200PWE, V500R002C00SPC300, V500R002C10, V500R002C10PWE, V500R002C30, V500R002C30PWE, V200R005C03, V200R003C00SPC100, V500R002C20, V500R001C00, V500R001C00SPC200, V500R001C00SPC600, V500R001C00SPC700, V500R001C20SPC300, V500R001C20SPC500, V500R001C20SPC600, V500R001C60SPC100, V500R001C60SPC101, V500R001C60SPC200, V500R001C60SPC300, V500R001C60SPC500, V500R001C60SPC600, V500R005C00SPC100, V100R001C20SPC100, V500R001C20SPC101, V500R001C80PWE, V100R001C00SPC200, V100R001C10SPC200, V100R001C10SPC201, V100R001C20SPC200, V500R001C00SPC050, V500R001C00SPC090, V500R001C30SPC500, V500R001C30SPC600, V500R001C30SPC600PWE, V500R001C30SPC601, V500R001C50SPC009, V500R001C50SPC100, V500R001C50SPC100PWE, V500R001C50SPC200, V500R001C50SPC200PWE, V500R001C50SPC300, V500R001C60, V500R001C60SPC100PWE, V500R001C60SPC200PWE, V500R005C00SPC102, V500R001C10, V500R001C10SPC100, V500R001C10SPC200, V500R003C00, V500R003C00SPC100, V200R003C50SPC700

Timeline

Official Publish: December 13th, 2019
Last Modified: August 4th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.