CVE-2019-5259

There is an information leakage vulnerability on some Huawei products(AR120-S;AR1200;AR1200-S;AR150;AR150-S;AR160;AR200;AR200-S;AR2200;AR2200-S;AR3200;AR3600). An attacker with low permissions can view some high-privilege information by running specific commands.Successful exploit could cause an information disclosure condition.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:huawei:ar120-s_firmware:v200r005c32:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar120-s_firmware:v200r006c10:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar120-s_firmware:v200r007c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar120-s_firmware:v200r008c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar120-s_firmware:v200r009c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar120-s_firmware:v200r010c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar120-s:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:huawei:ar1200_firmware:v200r005c20:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar1200_firmware:v200r005c32:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar1200_firmware:v200r006c10:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar1200_firmware:v200r007c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar1200_firmware:v200r008c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar1200_firmware:v200r009c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar1200:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:huawei:ar1200-s_firmware:v200r005c20:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar1200-s_firmware:v200r005c32:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar1200-s_firmware:v200r006c10:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar1200-s_firmware:v200r007c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar1200-s_firmware:v200r008c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar1200-s_firmware:v200r009c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar1200-s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:huawei:ar150_firmware:v200r005c20:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar150_firmware:v200r005c32:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar150_firmware:v200r006c10:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar150_firmware:v200r007c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar150_firmware:v200r008c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar150_firmware:v200r009c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar150:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:huawei:ar150-s_firmware:v200r005c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar150-s_firmware:v200r005c32:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar150-s_firmware:v200r006c10:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar150-s_firmware:v200r007c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar150-s_firmware:v200r008c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar150-s_firmware:v200r009c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar150-s:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:huawei:ar160_firmware:v200r005c20:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar160_firmware:v200r005c32:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar160_firmware:v200r006c10:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar160_firmware:v200r007c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar160_firmware:v200r008c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar160_firmware:v200r009c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar160:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
OR cpe:2.3:o:huawei:ar200_firmware:v200r005c20:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar200_firmware:v200r005c32:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar200_firmware:v200r006c10:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar200_firmware:v200r007c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar200_firmware:v200r008c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar200_firmware:v200r009c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar200:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
OR cpe:2.3:o:huawei:ar200-s_firmware:v200r005c20:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar200-s_firmware:v200r005c32:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar200-s_firmware:v200r006c10:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar200-s_firmware:v200r007c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar200-s_firmware:v200r008c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar200-s_firmware:v200r009c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar200-s:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
OR cpe:2.3:o:huawei:ar2200_firmware:v200r005c20:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar2200_firmware:v200r005c32:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar2200_firmware:v200r006c10:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar2200_firmware:v200r007c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar2200_firmware:v200r008c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar2200_firmware:v200r009c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar2200:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
OR cpe:2.3:o:huawei:ar2200-s_firmware:v200r005c20:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar2200-s_firmware:v200r005c32:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar2200-s_firmware:v200r006c10:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar2200-s_firmware:v200r007c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar2200-s_firmware:v200r008c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar2200-s_firmware:v200r009c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar2200-s:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
OR cpe:2.3:o:huawei:ar3200_firmware:v200r005c20:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar3200_firmware:v200r005c32:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar3200_firmware:v200r006c10:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar3200_firmware:v200r007c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar3200_firmware:v200r008c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar3200_firmware:v200r009c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar3200:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
OR cpe:2.3:o:huawei:ar3600_firmware:v200r006c10:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar3600_firmware:v200r007c00:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar3600_firmware:v200r008c50:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ar3600_firmware:v200r009c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ar3600:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:44

Type Values Removed Values Added
References () https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191211-01-vrp-en - Vendor Advisory () https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191211-01-vrp-en - Vendor Advisory

Information

Published : 2019-12-16 22:15

Updated : 2024-11-21 04:44


NVD link : CVE-2019-5259

Mitre link : CVE-2019-5259

CVE.ORG link : CVE-2019-5259


JSON object : View

Products Affected

huawei

  • ar3200_firmware
  • ar2200-s
  • ar200_firmware
  • ar3200
  • ar2200-s_firmware
  • ar200-s_firmware
  • ar120-s_firmware
  • ar160_firmware
  • ar1200-s_firmware
  • ar2200_firmware
  • ar200-s
  • ar160
  • ar1200_firmware
  • ar150-s
  • ar1200-s
  • ar120-s
  • ar3600
  • ar150-s_firmware
  • ar200
  • ar3600_firmware
  • ar2200
  • ar1200
  • ar150_firmware
  • ar150
CWE
CWE-269

Improper Privilege Management