QID 43859

Date Published: 2021-10-07

QID 43859: Huawei Router Digital Signature Verification Bypass Vulnerability (Huawei-SA-20190320-01-ar-en)

There is a digital signature verification bypass vulnerability in some Huawei routers. The vulnerability is due to the affected software improperly verifying digital signatures for the software image in the affected device. A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device. (Vulnerability ID: HWPSIRT-2019-01058)

A local attacker with high privilege may exploit the vulnerability to bypass integrity checks for software images and install a malicious software image on the affected device.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Refer to Huawei security advisory huawei-sa-20190320-01-ar-en for updates and patch information.
    Vendor References

    CVEs related to QID 43859

    Software Advisories
    Advisory ID Software Component Link
    huawei-sa-20190320-01-ar-en Huawei VRP URL Logo www.huawei.com/en/psirt/security-advisories/huawei-sa-20190320-01-ar-en