Vulnerabilities > CVE-2019-5231 - Incorrect Authorization vulnerability in Huawei P30 Firmware

047910
CVSS 4.6 - MEDIUM
Attack vector
PHYSICAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
low complexity
huawei
CWE-863

Summary

P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check when a user attempts to perform certain action. Successful exploit could allow the attacker to update a crafted package.

Vulnerable Configurations

Part Description Count
OS
Huawei
62
Hardware
Huawei
1

Common Weakness Enumeration (CWE)