Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-5210


Nova 5i pro and Nova 5 smartphones with versions earlier than 9.1.1.190(C00E190R6P2)and Versions earlier than 9.1.1.175(C00E170R3P2) have an improper validation of array index vulnerability. The system does not properly validate the input value before use it as an array index when processing certain image information. The attacker tricks the user into installing a malicious application, successful exploit could cause malicious code execution.


Published

2019-11-29T20:15:10.800

Last Modified

2024-11-21T04:44:31.280

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-129

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei nova_5i_pro_firmware < 9.1.1.190\(c00e190r6p2\) Yes
Hardware huawei nova_5i_pro - No
Operating System huawei nova_5_firmware < 9.1.1.175\(c00e170r3p2\) Yes
Hardware huawei nova_5 - No

References