cbcvebase.
CVE-2019-5264
published 2019-12-13

CVE-2019-5264: There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9…

PriorityP416medium4.6CVSS 3.1
AVPACLPRNUINSUCHINAN
EPSS
0.23%
14.3th percentile
There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition. Successful exploit could cause information disclosure.

Affected

25 ranges
VendorProductVersion rangeFixed in
huaweichangxiang_7s_firmware< 9.1.0.107\(c00e107r2p8t8\)9.1.0.107\(c00e107r2p8t8\)
huaweichangxiang_8_plus_firmware< 9.1.0.111\(c00e111r1p6t8\)9.1.0.111\(c00e111r1p6t8\)
huaweihonor_9_lite_firmware< 9.1.0.113\(c00e111r2p10t8\)9.1.0.113\(c00e111r2p10t8\)
huaweihonor_9_lite_firmware< 9.1.0.118\(c636e4r1p1t8\)9.1.0.118\(c636e4r1p1t8\)
huaweihonor_9_lite_firmware< 9.1.0.118\(c185e4r1p4t8\)9.1.0.118\(c185e4r1p4t8\)
huaweihonor_9_lite_firmware< 9.1.0.121\(c432e4r1p3t8\)9.1.0.121\(c432e4r1p3t8\)
huaweihonor_9i_firmware< 9.1.0.121\(c432e4r1p3t8\)9.1.0.121\(c432e4r1p3t8\)
huaweihonor_9i_firmware< 9.1.0.106\(sp53c636e2r1p4t8\)9.1.0.106\(sp53c636e2r1p4t8\)
huaweihonor_v10_firmware< 9.0.0.156\(c00e156r2p14t8\)9.0.0.156\(c00e156r2p14t8\)
huaweihonor_v10_firmware< 9.0.0.159\(c432e4r1p9t8\)9.0.0.159\(c432e4r1p9t8\)
huaweihonor_v10_firmware< 9.0.0.159\(c636e3r1p12t8\)9.0.0.159\(c636e3r1p12t8\)
huaweimate_10_firmware< 9.0.0.167\(c00e85r2p20t8\)9.0.0.167\(c00e85r2p20t8\)
huaweimate_10_firmware< 9.0.0.159\(c432e4r1p9t8\)9.0.0.159\(c432e4r1p9t8\)
huaweimate_10_firmware< 9.0.0.177\(c185e2r1p12t8\)9.0.0.177\(c185e2r1p12t8\)
huaweimate_10_firmware< 9.0.0.159\(c636e2r1p12t8\)9.0.0.159\(c636e2r1p12t8\)
huaweimate_10_pro_firmware< 9.0.0.167\(c00e87r2p15t8\)9.0.0.167\(c00e87r2p15t8\)
huaweimate_10_pro_firmware< 9.0.0.159\(c185e2r1p13t8\)9.0.0.159\(c185e2r1p13t8\)
huaweimate_10_pro_firmware< 9.0.0.161\(c432e4r1p11t8\)9.0.0.161\(c432e4r1p11t8\)
huaweimate_10_pro_firmware< 9.0.0.159\(c636e2r1p13t8\)9.0.0.159\(c636e2r1p13t8\)
huaweimate_9_firmware< 9.0.1.158\(c432e6r1p8t8\)9.0.1.158\(c432e6r1p8t8\)
huaweimate_9_firmware< 9.0.1.159\(c636e6r1p8t8\)9.0.1.159\(c636e6r1p8t8\)
huaweip-smart_firmware< 9.1.0.119\(c636e5r1p1t8\)9.1.0.119\(c636e5r1p1t8\)
huaweip-smart_firmware< 9.1.0.130\(c432e8r1p5t8\)9.1.0.130\(c432e8r1p5t8\)
huaweiy9_2018_firmware< 9.1.0.115\(c432e5r1p1t8\)9.1.0.115\(c432e5r1p1t8\)
huaweiy9_2018_firmware< 9.1.0.120\(c636e5r1p1t8\)9.1.0.120\(c636e5r1p1t8\)

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.