CVE-2019-5302
published 2020-04-27CVE-2019-5302: There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station…
medium5.3CVSS 3.1
AVAACHPRNUINSUCNINAH
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1 out of 2 vulnerabilities. Different than CVE-2020-5303. Affected products are: ALP-AL00B: earlier than 9.1.0.333(C00E333R2P1T8) ALP-L09: earlier than 9.1.0.300(C432E4R1P9T8) ALP-L29: earlier than 9.1.0.315(C636E5R1P13T8) BLA-L29C: earlier than 9.1.0.321(C636E4R1P14T8), earlier than 9.1.0.330(C432E6R1P12T8), earlier than 9.1.0.302(C635E4R1P13T8) Berkeley-AL20: earlier than 9.1.0.333(C00E333R2P1T8) Berkeley-L09: earlier than 9.1.0.350(C10E3R1P14T8), earlier than 9.1.0.351(C432E5R1P13T8), earlier than 9.1.0.350(C636E4R1P13T8) Charlotte-L09C: earlier than 9.1.0.311(C185E4R1P11T8), earlier than 9.1.0.345(C432E8R1P11T8) Charlotte-L29C: earlier than 9.1.0.325(C185E4R1P11T8), earlier than 9.1.0.335(C636E3R1P13T8), earlier than 9.1.0.345(C432E8R1P11T8), earlier than 9.1.0.336(C605E3R1P12T8) Columbia-AL10B: earlier than 9.1.0.333(C00E333R1P1T8) Columbia-L29D: earlier than 9.1.0.350(C461E3R1P11T8), earlier than 9.1.0.350(C185E3R1P12T8), earlier than 9.1.0.350(C10E5R1P14T8), earlier than 9.1.0.351(C432E5R1P13T8) Cornell-AL00A: earlier than 9.1.0.333(C00E333R1P1T8) Cornell-L29A: earlier than 9.1.0.328(C185E1R1P9T8), earlier than 9.1.0.328(C432E1R1P9T8), earlier than 9.1.0.330(C461E1R1P9T8), earlier than 9.1.0.328(C636E2R1P12T8) Emily-L09C: earlier than 9.1.0.336(C605E4R1P12T8), earlier than 9.1.0.311(C185E2R1P12T8), earlier than 9.1.0.345(C432E10R1P12T8) Emily-L29C: earlier than 9.1.0.311(C605E2R1P12T8), earlier than 9.1.0.311(C636E7R1P13T8), earlier than 9.1.0.311(C432E7R1P11T8) Ever-L29B: earlier than 9.1.0.311(C185E3R3P1), earlier than 9.1.0.310(C636E3R2P1), earlier than 9.1.0.310(C432E3R1P12) HUAWEI Mate 20: earlier than 9.1.0.131(C00E131R3P1) HUAWEI Mate 20 Pro:
Affected
148 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | alp-al00b | — | — |
| huawei | alp-al00b_firmware | < 9.1.0.333\(c00e333r2p1t8\) | 9.1.0.333\(c00e333r2p1t8\) |
| huawei | alp-l09 | — | — |
| huawei | alp-l09_firmware | < 9.1.0.300\(c432e4r1p9t8\) | 9.1.0.300\(c432e4r1p9t8\) |
| huawei | alp-l29 | — | — |
| huawei | alp-l29_firmware | < 9.1.0.315\(c636e5r1p13t8\) | 9.1.0.315\(c636e5r1p13t8\) |
| huawei | berkeley-al20 | — | — |
| huawei | berkeley-al20_firmware | < 9.1.0.333\(c00e333r2p1t8\) | 9.1.0.333\(c00e333r2p1t8\) |
| huawei | berkeley-l09 | — | — |
| huawei | berkeley-l09 | — | — |
| huawei | berkeley-l09 | — | — |
| huawei | berkeley-l09_firmware | < 9.1.0.350\(c10e3r1p14t8\) | 9.1.0.350\(c10e3r1p14t8\) |
| huawei | berkeley-l09_firmware | < 9.1.0.351\(c432e5r1p13t8\) | 9.1.0.351\(c432e5r1p13t8\) |
| huawei | berkeley-l09_firmware | < 9.1.0.350\(c636e4r1p13t8\) | 9.1.0.350\(c636e4r1p13t8\) |
| huawei | bla-l29c | — | — |
| huawei | bla-l29c | — | — |
| huawei | bla-l29c | — | — |
| huawei | bla-l29c_firmware | < 9.1.0.321\(c636e4r1p14t8\) | 9.1.0.321\(c636e4r1p14t8\) |
| huawei | bla-l29c_firmware | < 9.1.0.330\(c432e6r1p12t8\) | 9.1.0.330\(c432e6r1p12t8\) |
| huawei | bla-l29c_firmware | < 9.1.0.302\(c635e4r1p13t8\) | 9.1.0.302\(c635e4r1p13t8\) |
| huawei | charlotte-l09c | — | — |
| huawei | charlotte-l09c | — | — |
| huawei | charlotte-l09c_firmware | < 9.1.0.311\(c185e4r1p11t8\) | 9.1.0.311\(c185e4r1p11t8\) |
| huawei | charlotte-l09c_firmware | < 9.1.0.345\(c432e8r1p11t8\) | 9.1.0.345\(c432e8r1p11t8\) |
| huawei | charlotte-l29c | — | — |