First published: Tue Jun 04 2019(Updated: )
There is a man-in-the-middle (MITM) vulnerability on Huawei P30 smartphones versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), and P30 Pro versions before VOG-AL00 9.1.0.162 (C01E160R1P12/C01E160R2P1). When users establish connection and transfer data through Huawei Share, an attacker could sniff, spoof and do a series of operations to intrude the Huawei Share connection and launch a man-in-the-middle attack to obtain and tamper the data. (Vulnerability ID: HWPSIRT-2019-03109)
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P30 Pro Firmware | <vog-al00_9.1.0.162\(c01e160r1p12\/c01e160r2p1\) | |
HUAWEI P30 Pro | ||
Huawei P30 Firmware | <ele-al00_9.1.0.162\(c01e160r1p12\/c01e160r2p1\) | |
HUAWEI P30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-5215.
The severity level of CVE-2019-5215 is medium with a score of 6.8.
Huawei P30 smartphones versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), and P30 Pro versions before VOG-AL00 9.1.0.162 (C01E160R1P12/C01E160R2P1) are affected by this vulnerability.
This vulnerability allows a man-in-the-middle (MITM) attack on Huawei P30 smartphones, which can result in unauthorized access or interception of data.
To mitigate the risk, Huawei recommends updating the Huawei P30 smartphones to the latest version which includes the security patch for this vulnerability.