← Retour aux CVEs
CVE-2019-5226
MEDIUM5.5
Description
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.
Details CVE
Score CVSS v3.15.5
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie11/29/2019
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
huawei:hisuitehuawei:hisuite_firmwarehuawei:mate_20huawei:mate_20_firmwarehuawei:p30huawei:p30_firmwarehuawei:p30_prohuawei:p30_pro_firmware
Faiblesses (CWE)
CWE-346
References
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190904-01-smartphone-en(psirt@huawei.com)
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190904-01-smartphone-en(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.