S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
low·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2019-19411 Scanner

CVE-2019-19411 Scanner - Local File Inclusion (LFI) vulnerability in Huawei Firewall

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.6k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-19411
3.7
CVSS

USG9500 with versions of V500R001C30SPC100, V500R001C30SPC200, V500R001C30SPC600, V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC200 have an information leakage vulnerability. Due to improper processing of the initialization vector used in a specific encryption algorithm, an attacker who gains access to this cryptographic primitive may exploit this vulnerability to cause the value of the confidentiality associated with its use to be diminished.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
USG9500by n/a
V500R001C30SPC100,V500R001C30SPC200,V500R001C30SPC600,V500R001C60SPC500,V500R005C00SPC100,V500R005C00SPC200
Updated Aug 21, 2026View on NVD →
Detail

Huawei USG9500 series firewalls are widely utilized in enterprises and organizations for network security solutions. They are employed to protect sensitive data, prevent unauthorized access, and ensure network availability. The firewalls offer advanced features such as intrusion prevention, antivirus, and VPN functionalities. Users rely on these devices to secure their networks against external and internal threats. Network administrators use these products to control traffic, detect intrusions, and manage security policies. The firewalls are an essential component in securing small to large-scale network infrastructures.

The vulnerability in the Huawei USG9500 series pertains to Local File Inclusion, which occurs due to improper input handling. This kind of vulnerability can enable attackers to access restricted files on the server. Specifically, it allows malicious actors to include files on a server through the web browser. This can lead to unauthorized access to sensitive data or system configurations. Exploiting this vulnerability requires gaining access to certain cryptographic primitives. Attackers could leverage this to diminish the confidentiality of the encrypted data used by the system.

Technical details reveal that the vulnerability in Huawei USG9500 is linked to the improper processing of the initialization vector in an encryption algorithm. The vulnerable endpoint typically includes a file retrieval mechanism that does not properly validate paths. Attackers can exploit this by constructing malformed requests, incorporating traversal sequences that permit access outside designated directories. Successful exploitation demands a specific sequence of inputs and methods to bypass the existing protections and access restricted files like '/etc/passwd'. The vulnerability is noted to affect several specific firmware versions of the firewall.

Exploiting this vulnerability could allow attackers to read sensitive files and data, particularly those containing username and password hashes. It could lead to the exposure of critical system information, potentially aiding further attacks such as privilege escalation or deeper network intrusions. Organizations might experience unauthorized access to sensitive data, leading to data breaches. Additionally, the compromised systems may serve as entry points for more severe security incidents. Therefore, effective mitigation strategies are necessary to prevent exploitation.

REFERENCES

Solution Advice
  • Regularly update and patch the Huawei USG9500 firewalls to the latest firmware versions provided by Huawei.
  • Implement stringent access controls to prevent unauthorized administrative access to system files.
  • Conduct periodic security audits to identify and rectify weak points in file inclusion mechanisms.
  • Utilize intrusion detection/prevention systems to monitor for exploitation attempts against file include vulnerabilities.
  • Ensure proper sanitization and validation of all user inputs to prevent malicious entries.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-19411 Scanner - Local File Inclusion (LFI) vulnerability in Huawei Firewall | S4E