Insufficient Verification Flaw in Huawei Smartphones
CVE-2019-5246

6.2MEDIUM

Key Information:

Vendor
Huawei
Vendor
CVE Published:
13 November 2019

Summary

Huawei smartphones running specific versions of software are exposed to a vulnerability due to insufficient verification of parameters. An attacker can exploit this flaw by connecting to the affected devices, enabling high privilege access to execute malicious code or initiate a denial-of-service (DOS) attack. Users are encouraged to remain vigilant and update to secure versions as recommended by the vendor's security advisory.

Affected Version(s)

ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1)

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.