CVE-2019-5248
Description
CloudEngine 12800 has a DoS vulnerability. An attacker of a neighboring device sends a large number of specific packets. As a result, a memory leak occurs after the device uses the specific packet. As a result, the attacker can exploit this vulnerability to cause DoS attacks on the target device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A DoS vulnerability in Huawei CloudEngine 12800 switches allows a neighboring attacker to trigger memory leaks via specific packets, causing device denial of service.
Vulnerability
The vulnerability exists in the Huawei CloudEngine 12800 series switches running firmware versions V200R001C00SPC600, V200R001C00SPC700, V200R002C01, V200R002C50SPC800, and V200R002C50SPC800PWE [1]. The device fails to properly handle a large number of specially crafted packets from a neighboring device, leading to a memory leak that degrades device stability until denial of service occurs.
Exploitation
An attacker must be on a directly connected neighboring network segment to send the crafted packets to the target device [1]. No authentication is required, and the attack involves sending a high volume of specific packets to the affected switch. The memory leak accumulates as the device processes each malicious packet, eventually exhausting available memory and forcing a system crash or hang.
Impact
Successful exploitation causes a denial of service (DoS) condition on the target CloudEngine 12800 switch [1]. The device becomes unresponsive, disrupting network services and connectivity for all systems relying on that switch. The impact is limited to availability; there is no evidence of information disclosure or privilege escalation from this vulnerability.
Mitigation
Huawei has released software updates to address this vulnerability [1]. The fixed version is V200R005C10SPC800, released before the advisory date of December 4, 2019 [1]. Users must upgrade to V200R005C10SPC800 or later. There are no known workarounds, and the product is not listed on the CISA KEV catalog. Vulnerable versions that are no longer supported should be upgraded immediately.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- CloudEngine/CloudEngine 12800description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.huawei.com/en/psirt/security-advisories/huawei-sa-20191204-03-dos-enmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.