QID 43893

Date Published: 2021-11-02

QID 43893: Huawei Router and Switch Multiple Vulnerabilities (huawei-sa-20191211-01-ssp-en)

There is an out-of-bounds read vulnerability in some Huawei products. An attacker who logs in to the board may send crafted messages from the internal network port or tamper with inter-process message packets to exploit this vulnerability. Due to insufficient validation of the message, a successful exploit may cause the affected board abnormal. (Vulnerability ID: HWPSIRT-2019-01067) There is a DoS vulnerability in some Huawei products. An attacker may send crafted messages from a FTP client to exploit this vulnerability. Due to insufficient validation of the message, a successful exploit may cause the system out-of-bounds read and result in a denial of service condition of the affected service. (Vulnerability ID: HWPSIRT-2019-01071) There is a null pointer dereference vulnerability in some Huawei products. The system dereferences a pointer that it expects to be valid, but is NULL. A local attacker could exploit this vulnerability by sending crafted parameters. A successful exploit could cause a denial of service and the process reboot. (Vulnerability ID: HWPSIRT-2019-01072) There is a resource management vulnerability in some Huawei products. An attacker who logs in to the board may send crafted messages from the internal network port or tamper with inter-process message packets to exploit this vulnerability. Due to improper management of system resources, a successful exploit may cause resource exhaustion. (Vulnerability ID: HWPSIRT-2019-01073) There is a buffer overflow vulnerability in some Huawei products. An attacker who logs in to the board may send crafted messages from the internal network port or tamper with inter-process message packets to exploit this vulnerability. Due to insufficient validation of the message, successful exploit may cause the affected board abnormal. (Vulnerability ID: HWPSIRT-2019-01074)

HWPSIRT-2019-01067: Successful exploit may cause the affected board abnormal. HWPSIRT-2019-01071: Successful exploit may cause the system out-of-bounds read and result in a denial of service condition of the affected service. HWPSIRT-2019-01072: Successful exploit may cause a denial of service and the process reboot. HWPSIRT-2019-01073: Successful exploit may cause resource exhausted. HWPSIRT-2019-01074: Successful exploit may cause the affected board abnormal.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Huawei security advisory huawei-sa-20191211-01-ssp-en for updates and patch information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    huawei-sa-20191211-01-ssp-en URL Logo www.huawei.com/en/psirt/security-advisories/huawei-sa-20191211-01-ssp-en