Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-5221


There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker could crafted a file path when transporting file through Huawei Share, successful exploit could allow the attacker to transport a file to arbitrary path on the phone. Affected products: Mate 20 X versions earlier than Ever-L29B 9.1.0.300(C432E3R1P12), versions earlier than Ever-L29B 9.1.0.300(C636E3R2P1), and versions earlier than Ever-L29B 9.1.0.300(C185E3R3P1).


Published

2019-07-10T18:15:11.127

Last Modified

2024-11-21T04:44:32.990

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.5 (MEDIUM)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.5

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei mate_20_x_firmware < ever-l29b_9.1.0.300\(c636e3r2p1\) Yes
Hardware huawei mate_20_x - No
Operating System huawei mate_20_x_firmware < ever-l29b_9.1.0.300\(c432e3r1p12\) Yes
Hardware huawei mate_20_x - No
Operating System huawei mate_20_x_firmware < ever-l29b_9.1.0.300\(c185e3r3p1\) Yes
Hardware huawei mate_20_x - No

References