CVE-2019-5251

CWE-22Path Traversal3 documents3 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 67.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13
Latest updateMay 24

Description

There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

NVDhuawei/m6_firmware< 9.1.1.150\(c00e150r1p150\)
NVDhuawei/p30_firmware< 9.1.0.226\(c00e220r2p1\)
NVDhuawei/mate_20_firmware< 9.1.0.139\(c00e133r3p1\)
NVDhuawei/p30_pro_firmware< 9.1.0.226\(c00e210r2p1\)
NVDhuawei/enjoy_7s_firmware< 9.1.0.130\(c00e115r2p8t8\)

🔴Vulnerability Details

2
GHSA
GHSA-jr37-cw64-8v29: There is a path traversal vulnerability in several Huawei smartphones2022-05-24
CVEList
CVE-2019-5251: There is a path traversal vulnerability in several Huawei smartphones2019-12-13
CVE-2019-5251 (MEDIUM CVSS 5.5) | There is a path traversal vulnerabi | cvebase.io