First published: Wed Nov 13 2019(Updated: )
Honor 10 Lite, Honor 8A, Huawei Y6 mobile phones with the versions before 9.1.0.217(C00E215R3P1), the versions before 9.1.0.205(C00E97R1P9), the versions before 9.1.0.205(C00E97R2P2) have an information leak vulnerability. Due to improper function error records of some module, an attacker with the access permission may exploit the vulnerability to obtain some information.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Honor 10 Lite Firmware | <9.1.0.217\(c00e215r3p1\) | |
Huawei Honor 10 Lite | ||
Google Android | <9.1.0.205\(c00e97r1p9\) | |
Apple Sierra | ||
Huawei Huawei Y6 Firmware | <9.1.0.205\(c00e97r2p2\) | |
Huawei Huawei Y6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-5292.
Honor 10 Lite, Honor 8A, and Huawei Y6 mobile phones with the versions before 9.1.0.217(C00E215R3P1), 9.1.0.205(C00E97R1P9), and 9.1.0.205(C00E97R2P2) are affected by this vulnerability.
The severity of CVE-2019-5292 is low, with a severity value of 3.3.
CVE-2019-5292 is an information leak vulnerability in certain Huawei mobile phone models, including Honor 10 Lite, Honor 8A, and Huawei Y6. It is caused by improper function error records of some modules.
To fix CVE-2019-5292, Huawei recommends updating the affected mobile phone models to the versions 9.1.0.217(C00E215R3P1), 9.1.0.205(C00E97R1P9), or 9.1.0.205(C00E97R2P2).