Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-5251


There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.


Published

2019-12-13T15:15:11.317

Last Modified

2024-11-21T04:44:36.387

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei honor_v10_firmware < 9.1.0.333\(c00e333r2p1t8\) Yes
Hardware huawei honor_v10 - No
Operating System huawei p30_firmware < 9.1.0.226\(c00e220r2p1\) Yes
Hardware huawei p30 - No
Operating System huawei enjoy_7s_firmware < 9.1.0.130\(c00e115r2p8t8\) Yes
Hardware huawei enjoy_7s - No
Operating System huawei mate_20_firmware < 9.1.0.139\(c00e133r3p1\) Yes
Hardware huawei mate_20 - No
Operating System huawei honor_9_lite_firmware < 9.1.0.143\(c636e5r1p5t8\) Yes
Hardware huawei honor_9_lite - No
Operating System huawei honor_9i_firmware < 9.1.0.120\(c00e113r1p6t8\) Yes
Hardware huawei honor_9i - No
Operating System huawei m6_firmware < 9.1.1.150\(c00e150r1p150\) Yes
Hardware huawei m6 - No
Operating System huawei p30_pro_firmware < 9.1.0.226\(c00e210r2p1\) Yes
Hardware huawei p30_pro - No
Operating System huawei honor_20s_firmware < 9.1.1.132\(c00e131r6p1\) Yes
Hardware huawei honor_20s - No
Operating System huawei honor_9_lite_firmware < 9.1.0.130\(c00e112r2p10t8\) Yes
Hardware huawei honor_9_lite - No

References