CVE-2019-5289
Last modified
CVE-2019-5289 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insufficient checks of the specific packet length. Attackers can construct invalid packets to attack the active and standby communication channels. EPSS estimates a 0.74% chance of exploitation in the next 30 days.
Description
Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insufficient checks of the specific packet length. Attackers can construct invalid packets to attack the active and standby communication channels. Successful exploit of this vulnerability could allow the attacker to crash the database on the standby node.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Manageone | 6.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5289?
How severe is CVE-2019-5289?
How do I fix CVE-2019-5289?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-5283There is Factory Reset Protection (FRP) bypass security vuln…
- CVE-2019-5284There is a DoS vulnerability in RTSP module of Leland-AL00A …6.5
- CVE-2019-5285Some Huawei S series switches have a DoS vulnerability. An u…
- CVE-2019-5286There is a reflection XSS vulnerability in the HedEx product…
- CVE-2019-5287P30 smart phones with versions earlier than ELLE-AL00B 9.1.0…7.8
- CVE-2019-5288P30 smart phones with versions earlier than ELLE-AL00B 9.1.0…7.8
- CVE-2019-5290Huawei S5700 and S6700 have a DoS security vulnerability. At…6.5
- CVE-2019-5291Some Huawei products have an insufficient verification of da…5.9
- CVE-2019-5292Honor 10 Lite, Honor 8A, Huawei Y6 mobile phones with the ve…3.3
- CVE-2019-5293Some Huawei products have a memory leak vulnerability when h…6.5
- CVE-2019-5294There is an out of bound read vulnerability in some Huawei p…7.5
- CVE-2019-5295Huawei Honor V10 smartphones versions earlier than Berkeley-…
Are you affected by CVE-2019-5289?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
