CVE-2019-15415: Low severity mi redmi 5 vulnerability
The Xiaomi Redmi 5 Android device with a build fingerprint of xiaomi/vince/vince:7.1.2/N2G47H/V9.5.4.0.NEGMIFA:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1711201803291645) that allows unauthorized wireless settings modification via a confused deputy attack. This capability can be accessed by any app co-located on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15415?
CVE-2019-15415 has a moderate severity rating due to its potential for unauthorized access to wireless settings.
How do I fix CVE-2019-15415?
To mitigate CVE-2019-15415, users should uninstall or disable the vulnerable pre-installed app on the affected Xiaomi Redmi 5 device.
Which devices are affected by CVE-2019-15415?
CVE-2019-15415 specifically affects the Xiaomi Redmi 5 with the mentioned build fingerprint and the vulnerable app version.
What type of vulnerability is CVE-2019-15415?
CVE-2019-15415 is classified as an unauthorized modification vulnerability related to wireless settings.
Is there a patch available for CVE-2019-15415?
As of now, Xiaomi has not released a specific patch for CVE-2019-15415, so users are advised to take manual actions to secure their devices.