QID 43879

Date Published: 2021-11-02

QID 43879: Huawei Router and Switch Weak Algorithm Vulnerability (huawei-sa-20191204-01-vrp-en)

There is a weak algorithm vulnerability in some Huawei products. The affected products use weak algorithms by default. Attackers may exploit the vulnerability to cause information leaks. (Vulnerability ID: HWPSIRT-2019-02008)

Successful exploit may cause information leaks.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Huawei security advisory huawei-sa-20191204-01-vrp-en for updates and patch information.Workaround:
    Users can disable weak algorithms by run command "ssh server cipher" or "ssh client cipher".
    Vendor References

    CVEs related to QID 43879

    Software Advisories
    Advisory ID Software Component Link
    huawei-sa-20191204-01-vrp-en URL Logo www.huawei.com/en/psirt/security-advisories/huawei-sa-20191204-01-vrp-en