Insufficient Verification Flaw in Huawei Smartphones
CVE-2019-5246
6.2MEDIUM
Summary
Huawei smartphones running specific versions of software are exposed to a vulnerability due to insufficient verification of parameters. An attacker can exploit this flaw by connecting to the affected devices, enabling high privilege access to execute malicious code or initiate a denial-of-service (DOS) attack. Users are encouraged to remain vigilant and update to secure versions as recommended by the vendor's security advisory.
Affected Version(s)
ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1)
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved