Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20191204-03-SMARTPHONE
HistoryDec 04, 2019 - 12:00 a.m.

Security Advisory - Path Traversal Vulnerability in Several Smartphones

2019-12-0400:00:00
Huawei Technologies
www.huawei.com
63

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

38.5%

There is a path traversal vulnerability in several smartphones. The system does not sufficiently validate certain pathname from the application, an attacker should trick the user into installing, backing up and restoring a malicious application, successful exploit could cause information disclosure. (Vulnerability ID: HWPSIRT-2019-06112)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2019-5251.

Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191204-03-smartphone-en

Affected configurations

Vulners
Node
huaweianne-al00_firmwareRange<9.1.0.126
OR
huaweibla-l29c_firmwareRange<9.1.0.321
OR
huaweibla-l29c_firmwareRange<9.1.0.325
OR
huaweibla-l29c_firmwareRange<9.1.0.341
OR
huaweibla-l29c_firmwareRange<9.1.0.345
OR
huaweibla-l29c_firmwareRange<9.1.0.346
OR
huaweibla-tl00b_firmwareRange<9.1.0.333
OR
huaweitag-al00_firmwareRange<9.1.0.333
OR
huaweiberkeley-al20_firmwareRange<9.1.0.333
OR
huaweiberkeley-l09_firmwareRange<9.1.0.350
OR
huaweiberkeley-l09_firmwareRange<9.1.0.350
OR
huaweiberkeley-l09_firmwareRange<9.1.0.351
OR
huaweiberkeley-tl10_firmwareRange<9.1.0.333
OR
huaweiever-l29b_firmwareRange<10.0.0.183
OR
huaweiever-l29b_firmwareRange<10.0.0.183
OR
huaweiever-l29b_firmwareRange<10.0.0.184
OR
huaweifigo-tl10b_firmwareRange<9.1.0.130
OR
huaweifigo-l23_firmwareRange<9.1.0.137
OR
huaweifigo-l31_firmwareRange<9.1.0.137
OR
huaweifigo-l31_firmwareRange<9.1.0.137
OR
huaweifigo-l31_firmwareRange<9.1.0.142
OR
huaweifigo-l31_firmwareRange<9.1.0.151
OR
huaweifigo-tl10b_firmwareRange<9.1.0.130
OR
huaweiflorida-al20b_firmwareRange<9.1.0.136
OR
huaweiflorida-l21_firmwareRange<9.1.0.139
OR
huaweiflorida-l21_firmwareRange<9.1.0.143
OR
huaweiflorida-l22_firmwareRange<9.1.0.143
OR
huaweiflorida-l23_firmwareRange<9.1.0.144
OR
huaweiflorida-tl10b_firmwareRange<9.1.0.136
OR
huaweihonor_20_firmwareRange<9.1.0.149
OR
huaweihonor_20_pro_firmwareRange<9.1.0.170
OR
huaweihonor_20_pro_firmwareRange<9.1.0.170
OR
huaweihonor_20_pro_firmwareRange<9.1.0.171
OR
huaweihonor_20_pro_firmwareRange<9.1.0.172
OR
huaweihonor_20_pro_firmwareRange<9.1.0.172
OR
huaweimate_20_firmwareRange<9.1.0.139
OR
huaweimate_20_firmwareRange<9.1.0.139
OR
huaweimate_20_pro_firmwareRange<10.0.0.180
OR
huaweimate_20_pro_firmwareRange<10.0.0.180
OR
huaweimate_20_pro_firmwareRange<10.0.0.181
OR
huaweimate_20_pro_firmwareRange<10.0.0.187
OR
huaweimate_20_x_firmwareRange<10.0.0.188
OR
huaweimate_20_x_firmwareRange<10.0.0.188
OR
huaweip_smart_firmwareRange<9.1.0.148
OR
huaweip20_lite_firmwareRange<9.1.0.246
OR
huaweip20_lite_firmwareRange<9.1.0.246
OR
huaweip20_lite_firmwareRange<9.1.0.246
OR
huaweip30_firmwareRange<9.1.0.226
OR
huaweip30_pro_firmwareRange<9.1.0.226
OR
huaweip30_pro_firmwareRange<9.1.0.226
OR
huaweinova_2s_firmwareRange<9.1.0.210
OR
huaweinova_2s_firmwareRange<9.1.0.210
OR
huaweinova_3e_firmwareRange<9.1.0.126
OR
huaweinova_3e_firmwareRange<9.1.0.237
OR
huaweinova_3e_firmwareRange<9.1.0.246
OR
huaweinova_3e_firmwareRange<9.1.0.246
OR
huaweihonor_view_10_firmwareRange<9.0.0.240
OR
huaweihonor_view_20_firmwareRange<10.0.0.171
OR
huaweihonor_view_20_firmwareRange<10.0.0.171
OR
huaweihonor_view_20_firmwareRange<10.0.0.171
OR
huaweihonor_view_20_firmwareRange<10.0.0.171
OR
huaweihonor_view_20_firmwareRange<10.0.0.172
OR
huaweilaya-al00ep_firmwareRange<10.0.0.188
OR
huaweileland-al00a_firmwareRange<9.1.0.130
OR
huaweileland-l21a_firmwareRange<9.1.0.143
OR
huaweileland-l22c_firmwareRange<9.1.0.143
OR
huaweileland-l31a_firmwareRange<9.1.0.134
OR
huaweileland-l32a_firmwareRange<9.1.0.139
OR
huaweileland-l32c_firmwareRange<9.1.0.139
OR
huaweileland-l42a_firmwareRange<9.1.0.139
OR
huaweileland-l42c_firmwareRange<9.1.0.139
OR
huaweileland-tl10b_firmwareRange<9.1.0.130
OR
huaweileland-tl10c_firmwareRange<9.1.0.130
OR
huaweilelandp-al00c_firmwareRange<9.1.0.120
OR
huaweilelandp-al10b_firmwareRange<9.1.0.120
OR
huaweilelandp-al10d_firmwareRange<9.1.0.120
OR
huaweilelandp-l22a_firmwareRange<9.1.0.124
OR
huaweilelandp-l22c_firmwareRange<9.1.0.139
OR
huaweilelandp-l22d_firmwareRange<9.1.0.139
OR
huaweineo-al00d_firmwareRange<10.0.0.156
OR
huaweiprinceton-al10d_firmwareRange<10.0.0.176
OR
huaweitony-al00b_firmwareRange<10.0.0.187
OR
huaweitony-tl00b_firmwareRange<10.0.0.175
OR
huaweiyale-al00a_firmwareRange<9.1.0.179
OR
huaweiyale-al50a_firmwareRange<9.1.1.132
OR
huaweiyale-l21a_firmwareRange<9.1.0.169
OR
huaweiyale-l21a_firmwareRange<9.1.0.169
OR
huaweiyale-l21a_firmwareRange<9.1.0.170
OR
huaweiyale-l21a_firmwareRange<9.1.0.170
OR
huaweiyale-l21a_firmwareRange<9.1.0.170
OR
huaweiyale-l21a_firmwareRange<9.1.0.171
OR
huaweiyale-tl00b_firmwareRange<9.1.0.179
OR
huaweiyalep-al10b_firmwareRange<9.1.0.179
VendorProductVersionCPE
huaweianne-al00_firmware*cpe:2.3:o:huawei:anne-al00_firmware:*:*:*:*:*:*:*:*
huaweibla-l29c_firmware*cpe:2.3:o:huawei:bla-l29c_firmware:*:*:*:*:*:*:*:*
huaweibla-tl00b_firmware*cpe:2.3:o:huawei:bla-tl00b_firmware:*:*:*:*:*:*:*:*
huaweitag-al00_firmware*cpe:2.3:o:huawei:tag-al00_firmware:*:*:*:*:*:*:*:*
huaweiberkeley-al20_firmware*cpe:2.3:o:huawei:berkeley-al20_firmware:*:*:*:*:*:*:*:*
huaweiberkeley-l09_firmware*cpe:2.3:o:huawei:berkeley-l09_firmware:*:*:*:*:*:*:*:*
huaweiberkeley-tl10_firmware*cpe:2.3:o:huawei:berkeley-tl10_firmware:*:*:*:*:*:*:*:*
huaweiever-l29b_firmware*cpe:2.3:o:huawei:ever-l29b_firmware:*:*:*:*:*:*:*:*
huaweifigo-tl10b_firmware*cpe:2.3:o:huawei:figo-tl10b_firmware:*:*:*:*:*:*:*:*
huaweifigo-l23_firmware*cpe:2.3:o:huawei:figo-l23_firmware:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 551

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

38.5%

Related for HUAWEI-SA-20191204-03-SMARTPHONE