Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-5227

EPSS 0.06% · P18
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-5227

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
多款Huawei产品输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Huawei P30等都是中国华为(Huawei)公司的产品。Huawei P30是一款智能手机。Huawei P30 Pro是一款智能手机。Huawei HiSuite是一款用于PC端的手机助手应用程序。 多款Huawei产品中存在安全漏洞,该漏洞源于手机及手机助手软件对升级包没有进行充分地校验。攻击者可利用该漏洞导致手机系统被降级到较老的版本。以下产品及版本受到影响:Huawei P30 ELLE-AL00B 9.1.0.193(C00E190R2P1)之前的版本;P30 Pro VOGUE-AL00
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-P30, P30 Pro, Mate 20, HiSuite Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), Versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1), Versions earlier than HiSuite 9.1.0.305 -

II. Public POCs for CVE-2019-5227

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-5227

登录查看更多情报信息。

Same Patch Batch · n/a · 2019-11-29 · 24 CVEs total

CVE-2019-5211Huawei P20 输入验证错误漏洞
CVE-2019-19391LuaJIT 安全漏洞
CVE-2019-19377Linux kernel 资源管理错误漏洞
CVE-2019-19378Linux kernel 缓冲区错误漏洞
CVE-2019-18922Allied Telesis AT-GS950/8 路径遍历漏洞
CVE-2019-5226多款Huawei产品输入验证错误漏洞
CVE-2019-5225Huawei P30、Mate 20和P30 Pro 缓冲区错误漏洞
CVE-2019-5224Huawei P30 缓冲区错误漏洞
CVE-2019-5263Huawei HiSuite和HwBackup 信息泄露漏洞
CVE-2019-5210Huawei Nova 5i pro和Nova 5 输入验证错误漏洞
CVE-2019-5212Huawei P20 访问控制错误漏洞
CVE-2019-5232Huawei VP9630、VP9650和VP9660 安全特征问题漏洞
CVE-2019-19451GNOME Dia 安全漏洞
CVE-2019-5218Huawei 华为手环2和荣耀手环3 授权问题漏洞
CVE-2019-5269多款Huawei产品安全漏洞
CVE-2019-5268多款Huawei产品输入验证错误漏洞
CVE-2019-5247Huawei Atlas 300和Atlas 500 缓冲区错误漏洞
CVE-2019-5308Huawei Mate 20 RS 授权问题漏洞
CVE-2019-5271Huawei Myna 信息泄露漏洞
CVE-2019-5309Huawei Honor Play 信息泄露漏洞

Showing top 20 of 24 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-5227

No comments yet


Leave a comment