ID

VAR-201911-0265


CVE

CVE-2019-5288


TITLE

P30 Integer overflow vulnerability in smartphones

Trust: 0.8

sources: JVNDB: JVNDB-2019-012018

DESCRIPTION

P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due to insufficient check on specific parameters. An attacker tricks the user into installing a malicious application, obtains the root permission and constructs specific parameters to the camera program to exploit this vulnerability. Successful exploit could cause the program to break down or allow for arbitrary code execution. P30 Smartphones contain an integer overflow vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. The Huawei P30 is a smartphone from China's Huawei

Trust: 2.16

sources: NVD: CVE-2019-5288 // JVNDB: JVNDB-2019-012018 // CNVD: CNVD-2019-33477

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-33477

AFFECTED PRODUCTS

vendor:huaweimodel:p30scope:eqversion: -

Trust: 1.2

vendor:huaweimodel:p30scope:ltversion:elle-al00b_9.1.0.193\(c00e190r2p1\)

Trust: 1.0

vendor:huaweimodel:p30scope:ltversion:elle-al00b 9.1.0.193(c00e190r2p1)

Trust: 0.8

vendor:huaweimodel:p30 <elle-al00b 9.1.0.193scope: - version: -

Trust: 0.6

vendor:huaweimodel:p30scope:eqversion:9.1.0.193c00e190r2p1

Trust: 0.6

vendor:huaweimodel:p30scope:eqversion:elle-al00b_9.1.0.186c00e180r2p1

Trust: 0.6

vendor:huaweimodel:p30scope:eqversion:elle-al00b_9.1.0.193c00e190r1p21

Trust: 0.6

vendor:huaweimodel:p30scope:eqversion:9.1.0.226c00e220r2p1

Trust: 0.6

vendor:huaweimodel:p30scope:eqversion:10.0.0.166c00e66r1p11

Trust: 0.6

vendor:huaweimodel:p30scope:eqversion:10.0.0.173c00e73r1p11

Trust: 0.6

sources: CNVD: CNVD-2019-33477 // JVNDB: JVNDB-2019-012018 // CNNVD: CNNVD-201909-1203 // NVD: CVE-2019-5288

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-5288
value: HIGH

Trust: 1.0

NVD: CVE-2019-5288
value: HIGH

Trust: 0.8

CNVD: CNVD-2019-33477
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201909-1203
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2019-5288
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-33477
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2019-5288
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2019-5288
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2019-33477 // JVNDB: JVNDB-2019-012018 // CNNVD: CNNVD-201909-1203 // NVD: CVE-2019-5288

PROBLEMTYPE DATA

problemtype:CWE-190

Trust: 1.8

sources: JVNDB: JVNDB-2019-012018 // NVD: CVE-2019-5288

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201909-1203

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-201909-1203

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-012018

PATCH

title:huawei-sa-20190925-01-smartphoneurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190925-01-smartphone-en

Trust: 0.8

title:Patch for Huawei P30 Plastic Overflow Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/182415

Trust: 0.6

title:Huawei P30 Enter the fix for the verification error vulnerabilityurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=98608

Trust: 0.6

sources: CNVD: CNVD-2019-33477 // JVNDB: JVNDB-2019-012018 // CNNVD: CNNVD-201909-1203

EXTERNAL IDS

db:NVDid:CVE-2019-5288

Trust: 3.0

db:JVNDBid:JVNDB-2019-012018

Trust: 0.8

db:CNVDid:CNVD-2019-33477

Trust: 0.6

db:CNNVDid:CNNVD-201909-1203

Trust: 0.6

sources: CNVD: CNVD-2019-33477 // JVNDB: JVNDB-2019-012018 // CNNVD: CNNVD-201909-1203 // NVD: CVE-2019-5288

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190925-01-smartphone-en

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2019-5288

Trust: 1.4

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20190925-01-smartphone-cn

Trust: 1.2

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-5288

Trust: 0.8

sources: CNVD: CNVD-2019-33477 // JVNDB: JVNDB-2019-012018 // CNNVD: CNNVD-201909-1203 // NVD: CVE-2019-5288

SOURCES

db:CNVDid:CNVD-2019-33477
db:JVNDBid:JVNDB-2019-012018
db:CNNVDid:CNNVD-201909-1203
db:NVDid:CVE-2019-5288

LAST UPDATE DATE

2024-11-23T22:33:40.388000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-33477date:2019-09-27T00:00:00
db:JVNDBid:JVNDB-2019-012018date:2019-11-22T00:00:00
db:CNNVDid:CNNVD-201909-1203date:2019-11-19T00:00:00
db:NVDid:CVE-2019-5288date:2024-11-21T04:44:40.677

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-33477date:2019-09-27T00:00:00
db:JVNDBid:JVNDB-2019-012018date:2019-11-22T00:00:00
db:CNNVDid:CNNVD-201909-1203date:2019-09-25T00:00:00
db:NVDid:CVE-2019-5288date:2019-11-13T15:15:10.400