CVE-2019-5215: Medium severity huawei p30 pro firmware vulnerability
There is a man-in-the-middle (MITM) vulnerability on Huawei P30 smartphones versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), and P30 Pro versions before VOG-AL00 9.1.0.162 (C01E160R1P12/C01E160R2P1). When users establish connection and transfer data through Huawei Share, an attacker could sniff, spoof and do a series of operations to intrude the Huawei Share connection and launch a man-in-the-middle attack to obtain and tamper the data. (Vulnerability ID: HWPSIRT-2019-03109)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-5215.
What is the severity level of CVE-2019-5215?
The severity level of CVE-2019-5215 is medium with a score of 6.8.
Which Huawei P30 smartphone versions are affected by this vulnerability?
Huawei P30 smartphones versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), and P30 Pro versions before VOG-AL00 9.1.0.162 (C01E160R1P12/C01E160R2P1) are affected by this vulnerability.
What is the risk of this vulnerability?
This vulnerability allows a man-in-the-middle (MITM) attack on Huawei P30 smartphones, which can result in unauthorized access or interception of data.
Is there a fix available for CVE-2019-5215?
To mitigate the risk, Huawei recommends updating the Huawei P30 smartphones to the latest version which includes the security patch for this vulnerability.