PT-2019-4372 · Honor+1 · Honor View 20+12

Published

2019-08-14

·

Updated

2020-05-05

·

CVE-2019-5302

CVSS v3.1

5.3

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Huawei smartphones versions earlier than 9.1.0.333(C00E333R2P1T8) Huawei Mate 20 versions earlier than 9.1.0.131(C00E131R3P1) Huawei Mate 20 Pro versions earlier than 9.1.0.310(C185E10R2P1) Huawei Mate 20 RS versions earlier than 9.1.0.135(C786E133R3P1) Huawei Mate 20 X versions earlier than 9.1.0.135(C00E133R2P1) Huawei P20 versions earlier than 9.1.0.333(C00E333R1P1T8) Huawei P20 Pro versions earlier than 9.1.0.333(C00E333R1P1T8) Huawei P30 versions earlier than 9.1.0.193 Huawei P30 Pro versions earlier than 9.1.0.186(C00E180R2P1) Huawei Y9 2019 versions earlier than 9.1.0.220(C605E3R1P1T8) Huawei nova lite 3 versions earlier than 9.1.0.305(C635E8R2P2) Honor 10 Lite versions earlier than 9.1.0.283(C605E8R2P2) Honor 8X versions earlier than 9.1.0.221(C461E2R1P1T8) Honor View 20 versions earlier than 9.1.0.238(C432E1R3P1) Honor 20 versions earlier than 9.1.0.152(C00E150R5P1) Honor Magic2 versions earlier than 10.0.0.187 Honor V20 versions earlier than 9.1.0.234(C00E234R4P3)
Description The issue exists due to insufficient input validation of TD-SCDMA messages. An attacker may send specially crafted messages from a rogue base station to the affected devices, potentially causing device abnormal.
Recommendations For versions earlier than 9.1.0.333(C00E333R2P1T8), update to a version later than 9.1.0.333(C00E333R2P1T8) to resolve the issue. For Huawei Mate 20 versions earlier than 9.1.0.131(C00E131R3P1), update to a version later than 9.1.0.131(C00E131R3P1) to resolve the issue. For Huawei Mate 20 Pro versions earlier than 9.1.0.310(C185E10R2P1), update to a version later than 9.1.0.310(C185E10R2P1) to resolve the issue. For Huawei Mate 20 RS versions earlier than 9.1.0.135(C786E133R3P1), update to a version later than 9.1.0.135(C786E133R3P1) to resolve the issue. For Huawei Mate 20 X versions earlier than 9.1.0.135(C00E133R2P1), update to a version later than 9.1.0.135(C00E133R2P1) to resolve the issue. For Huawei P20 versions earlier than 9.1.0.333(C00E333R1P1T8), update to a version later than 9.1.0.333(C00E333R1P1T8) to resolve the issue. For Huawei P20 Pro versions earlier than 9.1.0.333(C00E333R1P1T8), update to a version later than 9.1.0.333(C00E333R1P1T8) to resolve the issue. For Huawei P30 versions earlier than 9.1.0.193, update to a version later than 9.1.0.193 to resolve the issue. For Huawei P30 Pro versions earlier than 9.1.0.186(C00E180R2P1), update to a version later than 9.1.0.186(C00E180R2P1) to resolve the issue. For Huawei Y9 2019 versions earlier than 9.1.0.220(C605E3R1P1T8), update to a version later than 9.1.0.220(C605E3R1P1T8) to resolve the issue. For Huawei nova lite 3 versions earlier than 9.1.0.305(C635E8R2P2), update to a version later than 9.1.0.305(C635E8R2P2) to resolve the issue. For Honor 10 Lite versions earlier than 9.1.0.283(C605E8R2P2), update to a version later than 9.1.0.283(C605E8R2P2) to resolve the issue. For Honor 8X versions earlier than 9.1.0.221(C461E2R1P1T8), update to a version later than 9.1.0.221(C461E2R1P1T8) to resolve the issue. For Honor View 20 versions earlier than 9.1.0.238(C432E1R3P1), update to a version later than 9.1.0.238(C432E1R3P1) to resolve the issue. For Honor 20 versions earlier than 9.1.0.152(C00E150R5P1), update to a version later than 9.1.0.152(C00E150R5P1) to resolve the issue. For Honor Magic2 versions earlier than 10.0.0.187, update to a version later than 10.0.0.187 to resolve the issue. For Honor V20 versions earlier than 9.1.0.234(C00E234R4P3), update to a version later than 9.1.0.234(C00E234R4P3) to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00093
CVE-2019-5302

Affected Products

Honor 10 Lite
Honor V20
Honor 8
Honor Magic2
Honor View 20
Huawei Mate 20
Huawei Mate 20 Pro
Huawei P20
Huawei P20 Pro
Huawei P30
Huawei P30 Pro
Huawei Y9 2019
Huawei Nova Lite 3