CVE-2019-5251

There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:honor_v10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_v10:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:huawei:enjoy_7s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:enjoy_7s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:mate_20:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:huawei:honor_9_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_9_lite:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:huawei:honor_9i_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_9i:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:huawei:m6_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:m6:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:p30_pro:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:huawei:honor_20s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_20s:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:huawei:honor_9_lite_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:honor_9_lite:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-12-13 15:15

Updated : 2024-02-04 20:39


NVD link : CVE-2019-5251

Mitre link : CVE-2019-5251

CVE.ORG link : CVE-2019-5251


JSON object : View

Products Affected

huawei

  • honor_20s_firmware
  • mate_20
  • m6
  • p30_pro
  • mate_20_firmware
  • p30_pro_firmware
  • honor_20s
  • enjoy_7s_firmware
  • honor_9i
  • p30
  • honor_9_lite_firmware
  • honor_9i_firmware
  • honor_v10_firmware
  • enjoy_7s
  • m6_firmware
  • honor_9_lite
  • p30_firmware
  • honor_v10
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')