Severity
7.8HIGH
EPSS
0.1%
top 69.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 24

Description

Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12), Versions earlier than Princeton-AL10B 9.1.0.233(C00E233R4P3) have a race condition vulnerability. The system does not lock certain function properly, when the function is called by multiple processes could cause out of bound write. An attacker tricks the user into installing a malicious application, successful ex

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDhuawei/honor_v20_firmware< princeton-al10b_9.1.0.233\(c00e233r4p3\)
NVDhuawei/p30_firmware< elle-al00b_9.1.0.193\(c00e190r1p21\)
NVDhuawei/p30_pro_firmware< vogue-al00a_9.1.0.193\(c00e190r1p12\)

🔴Vulnerability Details

2
GHSA
GHSA-46rj-wmc7-5p68: Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 92022-05-24
CVEList
CVE-2019-5228: Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 92019-11-12
CVE-2019-5228 (HIGH CVSS 7.8) | Certain detection module of P30 | cvebase.io