Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-5299

Опубликовано: 13 авг. 2019
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

Huawei mobile phones Hima-AL00Bhave with Versions earlier than HMA-AL00C00B175 have a signature verification bypass vulnerability. Attackers can induce users to install malicious applications. Due to a defect in the signature verification logic, the malicious applications can invoke specific interface to execute malicious code. A successful exploit may result in the execution of arbitrary code.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:huawei:hima-al00b_firmware:*:*:*:*:*:*:*:*
Версия до hma-al00c00b175 (исключая)
cpe:2.3:h:huawei:hima-al00b:-:*:*:*:*:*:*:*

EPSS

Процентиль: 24%
0.0008
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

Huawei mobile phones Hima-AL00Bhave with Versions earlier than HMA-AL00C00B175 have a signature verification bypass vulnerability. Attackers can induce users to install malicious applications. Due to a defect in the signature verification logic, the malicious applications can invoke specific interface to execute malicious code. A successful exploit may result in the execution of arbitrary code.

EPSS

Процентиль: 24%
0.0008
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-347