PT-2019-17563 · Huawei · Honor V10
Published
2019-06-06
·
Updated
2020-08-24
·
CVE-2019-5295
CVSS v3.1
6.4
Medium
| Vector | AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8)
Description
The issue is related to an authorization bypass due to improper authorization implementation logic. Attackers can bypass certain authorization scopes of smartphones by performing specific operations, allowing them to perform operations beyond the scope of authorization.
Recommendations
For versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8), update to Berkeley-AL20 9.0.0.125(C00E125R2P14T8) or a later version to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Honor V10