4.3
CVSSv2

CVE-2019-5251

Published: 13/12/2019 Updated: 18/12/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

huawei honor_v10_firmware

huawei p30_firmware

huawei enjoy_7s_firmware

huawei mate_20_firmware

huawei honor_9_lite_firmware

huawei honor_9i_firmware

huawei m6_firmware

huawei p30_pro_firmware

huawei honor_20s_firmware

Vendor Advisories

There is a path traversal vulnerability in several smartphones The system does not sufficiently validate certain pathname from the application, an attacker should trick the user into installing, backing up and restoring a malicious application, successful exploit could cause information disclosure (Vulnerability ID: HWPSIRT-2019-06112) This vulne ...