Buffer Overflow Vulnerability on Huawei Smartphones
CVE-2019-5225

7.8HIGH

Key Information:

Vendor
Huawei
Vendor
CVE Published:
29 November 2019

Summary

A buffer overflow vulnerability exists in Huawei P30, Mate 20, and P30 Pro smartphones prior to specific software versions. The issue arises from insufficient validation of certain length parameters transmitted by applications to the kernel. This flaw allows an attacker to exploit the vulnerability by tricking users into installing a malicious application, potentially leading to unauthorized execution of malicious code.

Affected Version(s)

P30, Mate 20, P30 Pro Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), Versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.