PT-2019-17566 · Huawei · Huawei Mobile Phones

Published

2019-08-13

·

Updated

2020-08-24

·

CVE-2019-5299

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Huawei mobile phones Hima-AL00B versions earlier than HMA-AL00C00B175
Description The issue is related to a signature verification bypass. Attackers can trick users into installing malicious applications, which can then invoke a specific interface to execute malicious code due to a defect in the signature verification logic. This can lead to the execution of arbitrary code.
Recommendations For versions earlier than HMA-AL00C00B00B175, update to version HMA-AL00C00B175 or later to resolve the issue. As a temporary workaround, consider restricting the installation of applications from untrusted sources to minimize the risk of exploitation.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-5299

Affected Products

Huawei Mobile Phones