First published: Fri Nov 29 2019(Updated: )
There is an improper access control vulnerability in Huawei Share. The software does not properly restrict access to certain file from certain application. An attacker tricks the user into installing a malicious application then establishing a connect to the attacker through Huawei Share, successful exploit could cause information disclosure.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P20 Firmware | <emily-l29c_9.1.0.311\(c10e2r1p13t8\) | |
HUAWEI P20 | ||
Huawei P20 Firmware | <emily-l29c_9.1.0.311\(c461e2r1p11t8\) | |
Huawei P20 Firmware | <emily-l29c_9.1.0.311\(c605e2r1p12t8\) | |
Huawei P20 Firmware | <emily-l29c_9.1.0.311\(c432e7r1p11t8\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-5212 is medium with a CVSS score of 5.5.
The vulnerability in Huawei Share allows an attacker to establish a connection to the victim's device through a malicious application.
The affected software versions include Huawei P20 Firmware with specific version numbers.
No, HUAWEI P20 is not affected by CVE-2019-5212.
To fix the vulnerability in Huawei Share, it is recommended to install the latest security updates provided by Huawei.