QID 43876

Date Published: 2021-11-02

QID 43876: Huawei Router and Switch Insufficient Verification of Data Authenticity Vulnerability (huawei-sa-20191204-01-validation-en)

Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated attacker has to intercept specific packets between two devices, modify the packets, and send the modified packets to the peer device. Due to insufficient verification of some fields in the packets, an attacker may exploit the vulnerability to cause the target device abnormal. (Vulnerability ID: HWPSIRT-2019-04076)

An attacker may exploit the vulnerability to cause the target device abnormal.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Refer to Huawei security advisory huawei-sa-20191204-01-validation-en for updates and patch information.
    Vendor References

    CVEs related to QID 43876

    Software Advisories
    Advisory ID Software Component Link
    huawei-sa-20191204-01-validation-en URL Logo www.huawei.com/en/psirt/security-advisories/huawei-sa-20191204-01-validation-en