PT-2019-17563 · Huawei · Honor V10

Publicado

2019-06-06

·

Atualizado

2020-08-24

·

CVE-2019-5295

CVSS v3.1

6.4

Média

VetorAV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8)
Description The issue is related to an authorization bypass due to improper authorization implementation logic. Attackers can bypass certain authorization scopes of smartphones by performing specific operations, allowing them to perform operations beyond the scope of authorization.
Recommendations For versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8), update to Berkeley-AL20 9.0.0.125(C00E125R2P14T8) or a later version to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2019-5295

Produtos afetados

Honor V10