First published: Thu Aug 08 2019(Updated: )
Huawei smart phones Honor V20 with the versions before 9.0.1.161(C00E161R2P2) have an information leak vulnerability. An attacker may trick a user into installing a malicious application. Due to coding error during layer information processing, attackers can exploit this vulnerability to obtain some layer information.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Honor View 20 Firmware | <9.0.1.161\(c00e161r2p2\) | |
Huawei Honor View 20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5301 has been classified as a high-severity information leak vulnerability.
To fix CVE-2019-5301, update your Huawei Honor V20 device to the firmware version 9.0.1.161(C00E161R2P2) or later.
CVE-2019-5301 affects Huawei Honor V20 devices running firmware versions prior to 9.0.1.161(C00E161R2P2).
Exploiting CVE-2019-5301 allows attackers to potentially obtain sensitive information from the affected device.
CVE-2019-5301 requires the attacker to trick the user into installing a malicious application, indicating it cannot be exploited fully remotely.