Huawei Honor 9I Firmware vulnerabilities

4 known vulnerabilities affecting huawei/honor_9i_firmware.

Total CVEs
4
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH1MEDIUM2LOW1

Vulnerabilities

Page 1 of 1
CVE-2019-5252LOWCVSS 3.5fixed in 9.1.0.115\(c00e113r1p6t8\)fixed in 9.1.0.122\(c636e4r1p4t8\)2019-12-14
CVE-2019-5252 [LOW] CWE-287 CVE-2019-5252: There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.
nvd
CVE-2019-5251MEDIUMCVSS 5.5fixed in 9.1.0.120\(c00e113r1p6t8\)2019-12-13
CVE-2019-5251 [MEDIUM] CWE-22 CVE-2019-5251: There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficien There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.
nvd
CVE-2019-5264MEDIUMCVSS 4.6fixed in 9.1.0.121\(c432e4r1p3t8\)fixed in 9.1.0.106\(sp53c636e2r1p4t8\)2019-12-13
CVE-2019-5264 [MEDIUM] CVE-2019-5264: There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro; There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition. Successful exploit could cause information disclosure.
nvd
CVE-2019-2215HIGHCVSS 7.8KEVPoCfixed in 9.1.0.130\(c00e112r2p10t8\)2019-10-11
CVE-2019-2215 [HIGH] CWE-416 CVE-2019-2215: A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kerne A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-14172009
nvd