Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-5292


Honor 10 Lite, Honor 8A, Huawei Y6 mobile phones with the versions before 9.1.0.217(C00E215R3P1), the versions before 9.1.0.205(C00E97R1P9), the versions before 9.1.0.205(C00E97R2P2) have an information leak vulnerability. Due to improper function error records of some module, an attacker with the access permission may exploit the vulnerability to obtain some information.


Published

2019-11-13T16:15:11.657

Last Modified

2024-11-21T04:44:41.157

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.3 (LOW)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei honor_10_lite_firmware < 9.1.0.217\(c00e215r3p1\) Yes
Hardware huawei honor_10_lite - No
Operating System huawei honor_8a_firmware < 9.1.0.205\(c00e97r1p9\) Yes
Hardware huawei honor_8a - No
Operating System huawei huawei_y6_firmware < 9.1.0.205\(c00e97r2p2\) Yes
Hardware huawei huawei_y6 - No

References