// For flags

CVE-2019-5230

 

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

P20 Pro, P20, Mate RS smartphones with versions earlier than Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than Emily-AL00A 9.1.0.321(C00E320R1P1T8), versions earlier than NEO-AL00D NEO-AL00 9.1.0.321(C786E320R1P1T8) have an improper validation vulnerability. The system does not perform a properly validation of certain input models, an attacker could trick the user to install a malicious application then craft a malformed model, successful exploit could allow the attacker to get and tamper certain output data information.

Teléfonos Inteligentes P20 Pro, P20, Mate RS con versiones anteriores a Charlotte-AL00A 9.1.0.321(C00E320R1P1T8), versiones anteriores a Emily-AL00A 9.1.0.321(C00E320R1P1T8), versiones anteriores a NEO-AL00D NEO-AL00 9.1.0.321(C786E320R1P1T8), presentan una vulnerabilidad de comprobación inapropiada. El sistema no realiza una comprobación apropiada de ciertos modelos de entrada, un atacante podría engañar al usuario para que instale una aplicación maliciosa y luego diseñe un modelo malformado, Una explotación con éxito podría permitirle al atacante obtener y manipular determinada información de datos de salida.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-01-04 CVE Reserved
  • 2019-11-12 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Huawei
Search vendor "Huawei"
P20 Pro Firmware
Search vendor "Huawei" for product "P20 Pro Firmware"
< charlotte-al00a_9.1.0.321\(c00e320r1p1t8\)
Search vendor "Huawei" for product "P20 Pro Firmware" and version " < charlotte-al00a_9.1.0.321\(c00e320r1p1t8\)"
-
Affected
in Huawei
Search vendor "Huawei"
P20 Pro
Search vendor "Huawei" for product "P20 Pro"
--
Safe
Huawei
Search vendor "Huawei"
P20 Firmware
Search vendor "Huawei" for product "P20 Firmware"
< emily-al00a_9.1.0.321\(c00e320r1p1t8\)
Search vendor "Huawei" for product "P20 Firmware" and version " < emily-al00a_9.1.0.321\(c00e320r1p1t8\)"
-
Affected
in Huawei
Search vendor "Huawei"
P20
Search vendor "Huawei" for product "P20"
--
Safe
Huawei
Search vendor "Huawei"
Mate Rs Firmware
Search vendor "Huawei" for product "Mate Rs Firmware"
< neo-al00d_neo-al00_9.1.0.321\(c786e320r1p1t8\)
Search vendor "Huawei" for product "Mate Rs Firmware" and version " < neo-al00d_neo-al00_9.1.0.321\(c786e320r1p1t8\)"
-
Affected
in Huawei
Search vendor "Huawei"
Mate Rs
Search vendor "Huawei" for product "Mate Rs"
--
Safe