PT-2019-17563 · Huawei · Honor V10

Published

2019-06-06

·

Updated

2020-08-24

·

CVE-2019-5295

CVSS v3.1

6.4

Medium

VectorAV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8)
Description The issue is related to an authorization bypass due to improper authorization implementation logic. Attackers can bypass certain authorization scopes of smartphones by performing specific operations, allowing them to perform operations beyond the scope of authorization.
Recommendations For versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8), update to Berkeley-AL20 9.0.0.125(C00E125R2P14T8) or a later version to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2019-5295

Affected Products

Honor V10