First published: Tue Nov 12 2019(Updated: )
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check when a user attempts to perform certain action. Successful exploit could allow the attacker to update a crafted package.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P30 Firmware | <elle-al00b_9.1.0.186\(c00e180r2p1\) | |
HUAWEI P30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-5231.
The severity level of CVE-2019-5231 is medium with a score of 4.6.
CVE-2019-5231 could allow an attacker to update a crafted package on P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1).
To fix CVE-2019-5231, update your P30 smartphone to version ELLE-AL00B 9.1.0.186(C00E180R2P1) or later.
You can find more information about CVE-2019-5231 in the security advisory published by Huawei: http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190930-01-smartphone-en.