CVE-2019-5222Incorrect Permission Assignment in Huawei Honor Magic 2 Firmware

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 74.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 17
Latest updateMay 24

Description

There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 9.1.0.216(C00E214R2P1). The Secure Input does not properly limit certain system privilege. An attacker tricks the user to install a malicious application and successful exploit could result in information disclosure.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDhuawei/honor_magic_2_firmware< tony-al00b_9.1.0.216\(c00e214r2p1\)
CVEListV5huawei/honor_magic_2_firmwareVersions earlier than Tony-AL00B 9.1.0.216(C00E214R2P1)

🔴Vulnerability Details

2
GHSA
GHSA-4fr2-64vg-vq77: There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 92022-05-24
CVEList
CVE-2019-5222: There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 92019-07-17
CVE-2019-5222 — Incorrect Permission Assignment | cvebase