CVE-2019-5212

Severity
5.5MEDIUM
EPSS
0.1%
top 69.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 29
Latest updateMay 24

Description

There is an improper access control vulnerability in Huawei Share. The software does not properly restrict access to certain file from certain application. An attacker tricks the user into installing a malicious application then establishing a connect to the attacker through Huawei Share, successful exploit could cause information disclosure.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDhuawei/p20_firmware< emily-l29c_9.1.0.311\(c10e2r1p13t8\)+3
CVEListV5p20Versions earlier than Emily-L29C 9.1.0.311(C10E2R1P13T8), Versions earlier than Emily-L29C 9.1.0.311(C461E2R1P11T8),Versions earlier than Emily-L29C 9.1.0.311(C605E2R1P12T8), Versions earlier than Emily-L29C 9.1.0.311(C432E7R1P11T8)

🔴Vulnerability Details

2
GHSA
GHSA-5mr2-62qq-29fg: There is an improper access control vulnerability in Huawei Share2022-05-24
CVEList
CVE-2019-5212: There is an improper access control vulnerability in Huawei Share2019-11-29
CVE-2019-5212 (MEDIUM CVSS 5.5) | There is an improper access control | cvebase.io