{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-23T23:58:44.098","vulnerabilities":[{"cve":{"id":"CVE-2019-5286","sourceIdentifier":"psirt@huawei.com","published":"2019-06-13T16:29:01.670","lastModified":"2026-06-17T02:37:26.493","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"There is a reflection XSS vulnerability in the HedEx products. Remote attackers send malicious links to users and trick users to click. Successfully exploit cloud allow the attacker to initiate XSS attacks. Affects HedEx Lite versions earlier than V200R006C00SPC007."},{"lang":"es","value":"Hay una vulnerabilidad XSS de reflexión en los productos HedEx. Los atacantes remotos envían enlaces maliciosos a los usuarios y los engañan para que hagan clic. La operación con éxito de la nube permite al atacante iniciar ataques XSS. Afecta las versiones de HedEx Lite anteriores a V200R006C00SPC007."}],"affected":[{"source":"psirt@huawei.com","affectedData":[{"vendor":"n/a","product":"HedEx Lite","versions":[{"version":"Versions earlier than V200R006C00SPC007","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:huawei:hedex_lite:*:*:*:*:*:*:*:*","versionEndExcluding":"v200r006c00spc007","matchCriteriaId":"E7CEE7B0-6061-4739-8B4B-F7A43D9FEA14"}]}]}],"references":[{"url":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190605-01-hedex-en","source":"psirt@huawei.com","tags":["Vendor Advisory"]},{"url":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190605-01-hedex-en","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}