Buffer Overflow Vulnerability on Huawei Smartphones
CVE-2019-5225
7.8HIGH
Summary
A buffer overflow vulnerability exists in Huawei P30, Mate 20, and P30 Pro smartphones prior to specific software versions. The issue arises from insufficient validation of certain length parameters transmitted by applications to the kernel. This flaw allows an attacker to exploit the vulnerability by tricking users into installing a malicious application, potentially leading to unauthorized execution of malicious code.
Affected Version(s)
P30, Mate 20, P30 Pro Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), Versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12)
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved