Vulnerability Details CVE-2019-5300
There is a digital signature verification bypass vulnerability in AR1200, AR1200-S, AR150, AR160, AR200, AR2200, AR2200-S, AR3200, SRG1300, SRG2300 and SRG3300 Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 1.0%
CVSS Severity
CVSS v3 Score 6.7
CVSS v2 Score 4.6
Products affected by CVE-2019-5300
-
cpe:2.3:h:huawei:ar1200e:-
-
cpe:2.3:h:huawei:ar1220c:-
-
cpe:2.3:h:huawei:ar1220ev:-
-
cpe:2.3:h:huawei:ar1220evw:-
-
cpe:2.3:h:huawei:ar1220f-s:-
-
cpe:2.3:h:huawei:ar158evw:-
-
-
cpe:2.3:h:huawei:ar161ew:-
-
cpe:2.3:h:huawei:ar161f-dgp:-
-
cpe:2.3:h:huawei:ar161f:-
-
cpe:2.3:h:huawei:ar161fg-l:-
-
cpe:2.3:h:huawei:ar161fgw-l:-
-
cpe:2.3:h:huawei:ar161fv-1p:-
-
cpe:2.3:h:huawei:ar161fw:-
-
cpe:2.3:h:huawei:ar161g-l:-
-
cpe:2.3:h:huawei:ar161w:-
-
cpe:2.3:h:huawei:ar168f-4p:-
-
cpe:2.3:h:huawei:ar168f:-
-
-
cpe:2.3:h:huawei:ar169egw-l:-
-
cpe:2.3:h:huawei:ar169ew:-
-
cpe:2.3:h:huawei:ar169f:-
-
cpe:2.3:h:huawei:ar169fgw-l:-
-
cpe:2.3:h:huawei:ar169fvw-8s:-
-
cpe:2.3:h:huawei:ar169fvw:-
-
cpe:2.3:h:huawei:ar169g-l:-
-
cpe:2.3:h:huawei:ar169jfvw-2s:-
-
cpe:2.3:h:huawei:ar169w:-
-
-
cpe:2.3:h:huawei:ar2200s:-
-
cpe:2.3:h:huawei:ar2204-27ge-p:-
-
cpe:2.3:h:huawei:ar2204-27ge:-
-
cpe:2.3:h:huawei:ar2204-51ge-p:-
-
cpe:2.3:h:huawei:ar2204e:-
-
cpe:2.3:h:huawei:ar2204xe:-
-
cpe:2.3:h:huawei:ar2220e:-
-
cpe:2.3:h:huawei:ar2240:-
-
cpe:2.3:h:huawei:ar2240c:-
-
cpe:2.3:h:huawei:ar3260:-
-
cpe:2.3:h:huawei:srg1320vw:-
-
cpe:2.3:h:huawei:srg2320e:-
-
cpe:2.3:h:huawei:srg3340:-
-
cpe:2.3:o:huawei:ar1200-s_firmware:v200r007c00
-
cpe:2.3:o:huawei:ar1200-s_firmware:v200r008c20
-
cpe:2.3:o:huawei:ar1200-s_firmware:v200r008c50
-
cpe:2.3:o:huawei:ar1200-s_firmware:v200r009c00
-
cpe:2.3:o:huawei:ar1200-s_firmware:v200r010c00
-
cpe:2.3:o:huawei:ar1200_firmware:v200r007c00
-
cpe:2.3:o:huawei:ar1200_firmware:v200r008c20
-
cpe:2.3:o:huawei:ar1200_firmware:v200r008c50
-
cpe:2.3:o:huawei:ar1200_firmware:v200r009c00
-
cpe:2.3:o:huawei:ar1200_firmware:v200r010c00
-
cpe:2.3:o:huawei:ar150_firmware:v200r007c00
-
cpe:2.3:o:huawei:ar150_firmware:v200r008c20
-
cpe:2.3:o:huawei:ar150_firmware:v200r008c50
-
cpe:2.3:o:huawei:ar150_firmware:v200r009c00
-
cpe:2.3:o:huawei:ar150_firmware:v200r010c00
-
cpe:2.3:o:huawei:ar160_firmware:v200r007c00
-
cpe:2.3:o:huawei:ar160_firmware:v200r008c20
-
cpe:2.3:o:huawei:ar160_firmware:v200r008c50
-
cpe:2.3:o:huawei:ar160_firmware:v200r009c00
-
cpe:2.3:o:huawei:ar160_firmware:v200r010c00
-
cpe:2.3:o:huawei:ar200_firmware:v200r007c00
-
cpe:2.3:o:huawei:ar200_firmware:v200r008c20
-
cpe:2.3:o:huawei:ar200_firmware:v200r008c50
-
cpe:2.3:o:huawei:ar200_firmware:v200r009c00
-
cpe:2.3:o:huawei:ar200_firmware:v200r010c00
-
cpe:2.3:o:huawei:ar2200_firmware:v200r007c00
-
cpe:2.3:o:huawei:ar2200_firmware:v200r008c20
-
cpe:2.3:o:huawei:ar2200_firmware:v200r008c50
-
cpe:2.3:o:huawei:ar2200_firmware:v200r009c00
-
cpe:2.3:o:huawei:ar2200_firmware:v200r010c00
-
cpe:2.3:o:huawei:ar2200s_firmware:v200r007c00
-
cpe:2.3:o:huawei:ar2200s_firmware:v200r008c20
-
cpe:2.3:o:huawei:ar2200s_firmware:v200r008c50
-
cpe:2.3:o:huawei:ar2200s_firmware:v200r009c00
-
cpe:2.3:o:huawei:ar2200s_firmware:v200r010c00
-
cpe:2.3:o:huawei:ar3200_firmware:v200r007c00
-
cpe:2.3:o:huawei:ar3200_firmware:v200r008c20
-
cpe:2.3:o:huawei:ar3200_firmware:v200r008c50
-
cpe:2.3:o:huawei:ar3200_firmware:v200r009c00
-
cpe:2.3:o:huawei:ar3200_firmware:v200r010c00
-
cpe:2.3:o:huawei:srg1300_firmware:v200r007c00
-
cpe:2.3:o:huawei:srg1300_firmware:v200r008c50
-
cpe:2.3:o:huawei:srg1300_firmware:v200r009c00
-
cpe:2.3:o:huawei:srg1300_firmware:v200r010c00
-
cpe:2.3:o:huawei:srg2300_firmware:v200r007c00
-
cpe:2.3:o:huawei:srg2300_firmware:v200r008c50
-
cpe:2.3:o:huawei:srg2300_firmware:v200r009c00
-
cpe:2.3:o:huawei:srg2300_firmware:v200r010c00
-
cpe:2.3:o:huawei:srg3300_firmware:v200r007c00
-
cpe:2.3:o:huawei:srg3300_firmware:v200r008c50
-
cpe:2.3:o:huawei:srg3300_firmware:v200r009c00
-
cpe:2.3:o:huawei:srg3300_firmware:v200r010c00