Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-5218


There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band.


Published

2019-11-29T20:15:11.020

Last Modified

2024-11-21T04:44:32.337

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.5

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei band_2_firmware < eris-b19\/eris-b29_1.2.53 Yes
Hardware huawei band_2 - No
Operating System huawei band_3_firmware < nyx-b10hn_1.5.53 Yes
Hardware huawei band_3 - No

References