Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-19411 PoC — Huawei USG9500 信息泄露漏洞

Source
Associated Vulnerability
Title:Huawei USG9500 信息泄露漏洞 (CVE-2019-19411)
Description:Huawei USG9500是中国华为(Huawei)公司的一款应用于大型环境的防火墙设备。该设备可提供高达T级的处理性能和99.999%可靠性,集成NAT、VPN、IPS、虚拟化、业务感知等多种安全特性,帮助企业构建面向云计算时代的数据中心边界安全防护,降低机房空间投资和每Mbps总体拥有成本。 Huawei USG9500中存在信息泄露漏洞,该漏洞源于对特定加密算法中使用的初始化向量处理不当。攻击者可通过获取该向量的访问权利用该漏洞削弱该向量相关的机密性。以下产品及版本受到影响:Huawei USG9
Description
USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 have an information leakage vulnerability. Due to improper processing of the initialization vector used in a specific encryption algorithm, an attacker who gains access to this cryptographic primitive may exploit this vulnerability to cause the value of the confidentiality associated with its use to be diminished.
File Snapshot

id: CVE-2019-19411 info: name: Huawei Firewall - Local File Inclusion author: taielab severit ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.