← Retour aux CVEs
CVE-2019-5228
HIGH7.8
Description
Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12), Versions earlier than Princeton-AL10B 9.1.0.233(C00E233R4P3) have a race condition vulnerability. The system does not lock certain function properly, when the function is called by multiple processes could cause out of bound write. An attacker tricks the user into installing a malicious application, successful exploit could cause malicious code execution.
Details CVE
Score CVSS v3.17.8
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie11/12/2019
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
huawei:honor_v20huawei:honor_v20_firmwarehuawei:p30huawei:p30_firmwarehuawei:p30_prohuawei:p30_pro_firmware
Faiblesses (CWE)
CWE-362CWE-787
References
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190911-01-smartphone-en(psirt@huawei.com)
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190911-01-smartphone-en(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.