« Volver al listado

CVE-2019-5248

Estado: ModificadaAlta (7.4)—

CloudEngine 12800 has a DoS vulnerability. An attacker of a neighboring device sends a large number of specific packets. As a result, a memory leak occurs after the device uses the specific packet. As a result, the attacker can exploit this vulnerability to cause DoS attacks on the target device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-5248",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.1,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.4,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@huawei.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "CloudEngine 12800",
          "versions": [
            {
              "status": "affected",
              "version": "V200R001C00SPC600"
            },
            {
              "status": "affected",
              "version": "V200R001C00SPC700"
            },
            {
              "status": "affected",
              "version": "V200R002C01"
            },
            {
              "status": "affected",
              "version": "V200R002C50SPC800"
            },
            {
              "status": "affected",
              "version": "V200R002C50SPC800PWE"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-12-13T15:15:11.193",
  "references": [
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191204-03-dos-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191204-03-dos-en",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-401"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CloudEngine 12800 has a DoS vulnerability. An attacker of a neighboring device sends a large number of specific packets. As a result, a memory leak occurs after the device uses the specific packet. As a result, the attacker can exploit this vulnerability to cause DoS attacks on the target device."
    },
    {
      "lang": "es",
      "value": "CloudEngine 12800 presenta una vulnerabilidad de DoS. Un atacante de un dispositivo vecino envía una gran cantidad de paquetes específicos. Como resultado, se produce una pérdida de memoria después de que el dispositivo utiliza el paquete específico. Como resultado, el atacante puede explotar esta vulnerabilidad para causar ataques de DoS en el dispositivo de destino."
    }
  ],
  "lastModified": "2026-06-17T02:37:22.230",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r001c00spc600:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1985052F-6452-46C7-8070-2CDB6FDF3803"
            },
            {
              "criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r001c00spc700:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA9CCEB1-6A35-4AE7-8F8D-EC137F663A85"
            },
            {
              "criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r002c01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A7B1A3E-5D5A-4E3A-89F1-73DA7FF0F060"
            },
            {
              "criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r002c50spc800:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2A1D568-48C6-4CE4-8CD2-93F79F484448"
            },
            {
              "criteria": "cpe:2.3:o:huawei:cloudengine_12800_firmware:v200r002c50spc800pwe:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30198A99-3F26-4A98-A001-633508FA0EF3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:huawei:cloudengine_12800:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DE8A2875-0F7E-4790-A925-5999396B7578"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@huawei.com"
}