PT-2019-4421 · Huawei · Huawei Nova 5+1

Publicado

2019-10-20

·

Atualizado

2019-12-05

·

CVE-2019-5210

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Huawei Nova 5i pro versions earlier than 9.1.1.190(C00E190R6P2) Huawei Nova 5 versions earlier than 9.1.1.175(C00E170R3P2)
Description The issue is related to improper validation of array index when processing certain image information. This could allow an attacker to trick a user into installing a malicious application, potentially leading to malicious code execution. The vulnerability is associated with unverified array indexing, which can be exploited by a specially crafted application.
Recommendations For Huawei Nova 5i pro versions earlier than 9.1.1.190(C00E190R6P2), update to version 9.1.1.190(C00E190R6P2) or later. For Huawei Nova 5 versions earlier than 9.1.1.175(C00E170R3P2), update to version 9.1.1.175(C00E170R3P2) or later. As a temporary workaround, consider restricting the installation of applications from untrusted sources to minimize the risk of exploitation.

Correção

Improper Validation of Array Index

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00164
CVE-2019-5210

Produtos afetados

Huawei Nova 5
Huawei Nova 5I Pro