First published: Wed Nov 13 2019(Updated: )
P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due to insufficient check on specific parameters. An attacker tricks the user into installing a malicious application, obtains the root permission and constructs specific parameters to the camera program to exploit this vulnerability. Successful exploit could cause the program to break down or allow for arbitrary code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P30 Firmware | <elle-al00b_9.1.0.193\(c00e190r2p1\) | |
HUAWEI P30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-5287.
The severity of CVE-2019-5287 is critical with a CVSS score of 7.8.
P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) are affected by CVE-2019-5287.
An attacker can exploit CVE-2019-5287 by tricking the user into installing a malicious application and obtaining root permission.
No, HUAWEI P30 is not affected by CVE-2019-5287.