CVE-2019-5228 Information
Feb 14, 2021
cve
Description
Certain detection module of P30 P30 Pro Honor V20 smartphone whith Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12) Versions earlier than Princeton-AL10B 9.1.0.233(C00E233R4P3) have a race condition vulnerability. The system does not lock certain function properly when the function is called by multiple processes could cause out of bound write. An attacker tricks the user into installing a malicious application successful exploit could cause malicious code execution.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190911-01-smartphone-en
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: