Exploit/Advisories no image

Published on December 15th, 2019 📆 | 4371 Views ⚑

0

Huawei AP2000 Management Messages privilege escalation


Convert Text to Speech

CVSS Meta Temp Score Current Exploit Price (β‰ˆ) CTI Interest Score
5.5 $5k-$25k 5.01

A vulnerability has been found in Huawei AP2000, IPS Module, NGFW Module, NIP6300, NIP6600, NIP6800, S5700, SVN5600, SVN5800, SVN5800-C, SeMG9811 and Secospace and classified as critical. This vulnerability affects an unknown code block of the component Management. The manipulation as part of a Messages leads to a privilege escalation vulnerability. The CWE definition for the vulnerability is CWE-269. As an impact it is known to affect confidentiality, integrity, and availability.

The weakness was presented 12/13/2019. This vulnerability was named CVE-2019-5257 since 01/04/2019. A single authentication is necessary for exploitation. There are neither technical details nor an exploit publicly available. The current price for an exploit might be approx. USD $5k-$25k (estimation calculated on 12/14/2019).

There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.

Vendor

Name

VulDB Meta Base Score: 5.5
VulDB Meta Temp Score: 5.5

VulDB Base Score: 5.5
VulDB Temp Score: 5.5
VulDB Vector: πŸ”’
VulDB Reliability: πŸ”

AV AC Au C I A
πŸ” πŸ” πŸ” πŸ” πŸ” πŸ”
πŸ” πŸ” πŸ” πŸ” πŸ” πŸ”
πŸ” πŸ” πŸ” πŸ” πŸ” πŸ”
Vector Complexity Authentication Confidentiality Integrity Availability
unlock unlock unlock unlock unlock unlock
unlock unlock unlock unlock unlock unlock
unlock unlock unlock unlock unlock unlock


VulDB Base Score: πŸ”’
VulDB Temp Score: πŸ”’
VulDB Reliability: πŸ”
Class: Privilege escalation (CWE-269)
Local: Yes
Remote: No





Availability: πŸ”’
Status: Not defined

Price Prediction: πŸ”
Current Price Estimation: πŸ”’


0-Day unlock unlock unlock unlock
Today unlock unlock unlock unlock

Threat Intelligenceinfoedit

Threat: πŸ”
Adversaries: πŸ”
Geopolitics: πŸ”
Economy: πŸ”
Predictions: πŸ”
Remediation: πŸ”Recommended: no mitigation known

0-Day Time: πŸ”’

01/04/2019 CVE assigned
12/13/2019 +343 days Advisory disclosed
12/14/2019 +1 days VulDB entry created
12/14/2019 +0 days VulDB last updateVendor: huawei.com
CVE: CVE-2019-5257 (πŸ”’)Created: 12/14/2019 06:55 PM
Complete: πŸ”

Check our Alexa App!

https://vuldb.com/?id.147208

Tagged with: β€’ β€’ β€’ β€’ β€’



Comments are closed.