CVE-2019-5221
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker could crafted a file path when transporting file through Huawei Share, successful exploit could allow the attacker to transport a file to arbitrary path on the phone. Affected products: Mate 20 X versions earlier than Ever-L29B 9.1.0.300(C432E3R1P12), versions earlier than Ever-L29B 9.1.0.300(C636E3R2P1), and versions earlier than Ever-L29B 9.1.0.300(C185E3R3P1).
Hay una vulnerabilidad de salto de ruta en la función Huawei Share. El software no comprueba apropiadamente la ruta, un atacante podría crear una ruta (path) de archivo al transportar un archivo por medio de Huawei Share, una explotación con éxito podría permitirle transportar un archivo a una ruta arbitraria en el teléfono. Productos afectados: Mate 20 X versiones anteriores a Ever-L29B 9.1.0.300(C432E3R1P12), versiones anteriores a Ever-L29B 9.1.0.300(C636E3R2P1) y versiones anteriores a Ever-L29B 9.1.0.300(C185E3R3P1).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-04 CVE Reserved
- 2019-07-10 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190703-01-share-en | 2019-07-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Mate 20 X Firmware Search vendor "Huawei" for product "Mate 20 X Firmware" | < ever-l29b_9.1.0.300\(c636e3r2p1\) Search vendor "Huawei" for product "Mate 20 X Firmware" and version " < ever-l29b_9.1.0.300\(c636e3r2p1\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Mate 20 X Search vendor "Huawei" for product "Mate 20 X" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Mate 20 X Firmware Search vendor "Huawei" for product "Mate 20 X Firmware" | < ever-l29b_9.1.0.300\(c432e3r1p12\) Search vendor "Huawei" for product "Mate 20 X Firmware" and version " < ever-l29b_9.1.0.300\(c432e3r1p12\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Mate 20 X Search vendor "Huawei" for product "Mate 20 X" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Mate 20 X Firmware Search vendor "Huawei" for product "Mate 20 X Firmware" | < ever-l29b_9.1.0.300\(c185e3r3p1\) Search vendor "Huawei" for product "Mate 20 X Firmware" and version " < ever-l29b_9.1.0.300\(c185e3r3p1\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Mate 20 X Search vendor "Huawei" for product "Mate 20 X" | - | - |
Safe
|