CVE-2019-5251
There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.
Published:Dec 13, 2019
Last Modified:Nov 21, 2024
EPS:Dec 13, 2019
EPSS Score:0.00131
CVSS Score:5.5
Affected Products
Vendor
Product
Action
Vendor
Huawei
Product
Enjoy 7s
Huawei
Enjoy 7s
Vendor
Huawei
Product
Enjoy 7s Firmware
Huawei
Enjoy 7s Firmware
Vendor
Huawei
Product
Honor 20s
Huawei
Honor 20s
Vendor
Huawei
Product
Honor 20s Firmware
Huawei
Honor 20s Firmware
Vendor
Huawei
Product
Honor 9 Lite
Huawei
Honor 9 Lite
Vendor
Huawei
Product
Honor 9 Lite Firmware
Huawei
Honor 9 Lite Firmware
Vendor
Huawei
Product
Honor 9i
Huawei
Honor 9i
Vendor
Huawei
Product
Honor 9i Firmware
Huawei
Honor 9i Firmware
Vendor
Huawei
Product
Honor V10
Huawei
Honor V10
Vendor
Huawei
Product
Honor V10 Firmware
Huawei
Honor V10 Firmware
Vendor
Huawei
Product
M6
Huawei
M6
Vendor
Huawei
Product
M6 Firmware
Huawei
M6 Firmware
Vendor
Huawei
Product
Mate 20
Huawei
Mate 20
Vendor
Huawei
Product
Mate 20 Firmware
Huawei
Mate 20 Firmware
Vendor
Huawei
Product
P30
Huawei
P30
Vendor
Huawei
Product
P30 Firmware
Huawei
P30 Firmware
Vendor
Huawei
Product
P30 Pro
Huawei
P30 Pro
Vendor
Huawei
Product
P30 Pro Firmware
Huawei
P30 Pro Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
