PT-2019-4289 · Huawei · Huawei Share+1

Publicado

2019-11-13

·

Atualizado

2020-08-24

·

CVE-2019-5212

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Huawei Share (affected versions not specified)
Description The issue is related to improper access control in Huawei Share, where the software fails to properly restrict access to certain files from certain applications. This could allow an attacker to trick a user into installing a malicious application and then establish a connection through Huawei Share, potentially leading to information disclosure. The vulnerability is also described as being related to a lack of protection for service data in the Huawei Share file sharing function on Huawei mobile phone software, such as the Huawei P20. Exploitation could enable a remote attacker to disclose protected information using a specially crafted application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00004
CVE-2019-5212

Produtos afetados

Huawei P20
Huawei Share