PT-2019-4289 · Huawei · Huawei Share+1
Published
2019-11-13
·
Updated
2020-08-24
·
CVE-2019-5212
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Huawei Share (affected versions not specified)
Description
The issue is related to improper access control in Huawei Share, where the software fails to properly restrict access to certain files from certain applications. This could allow an attacker to trick a user into installing a malicious application and then establish a connection through Huawei Share, potentially leading to information disclosure. The vulnerability is also described as being related to a lack of protection for service data in the Huawei Share file sharing function on Huawei mobile phone software, such as the Huawei P20. Exploitation could enable a remote attacker to disclose protected information using a specially crafted application.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Huawei P20
Huawei Share