CVE-2019-5295
CVE-2019-5295
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
06 jun 2019Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8) have an authorization bypass vulnerability. Due to improper authorization implementation logic, attackers can bypass certain authorization scopes of smart phones by performing specific operations. This vulnerability can be exploited to perform operations beyond the scope of authorization.
Productos afectados
Huawei · Honor V10¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →