PT-2019-17566 · Huawei · Huawei Mobile Phones
Published
2019-08-13
·
Updated
2020-08-24
·
CVE-2019-5299
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Huawei mobile phones Hima-AL00B versions earlier than HMA-AL00C00B175
Description
The issue is related to a signature verification bypass. Attackers can trick users into installing malicious applications, which can then invoke a specific interface to execute malicious code due to a defect in the signature verification logic. This can lead to the execution of arbitrary code.
Recommendations
For versions earlier than HMA-AL00C00B00B175, update to version HMA-AL00C00B175 or later to resolve the issue. As a temporary workaround, consider restricting the installation of applications from untrusted sources to minimize the risk of exploitation.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Mobile Phones