CVE-2019-5226
Last modified
CVE-2019-5226 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | P30 Firmware | < elle-al00b_9.1.0.193\(c00e190r2p1\) |
| Huawei | P30 Pro Firmware | < vogue-al00a_9.1.0.193\(c00e190r2p1\) |
| Huawei | Mate 20 Firmware | < hima-al00b_9.1.0.135\(c00e133r2p1\) |
| Huawei | Hisuite Firmware | < 9.1.0.305 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5226?
How severe is CVE-2019-5226?
How do I fix CVE-2019-5226?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-5220There is a Factory Reset Protection (FRP) bypass vulnerabili…
- CVE-2019-5221There is a path traversal vulnerability on Huawei Share. The…
- CVE-2019-5222There is an information disclosure vulnerability on Secure I…
- CVE-2019-5223PCManager 9.1.3.1 has an improper authentication vulnerabili…
- CVE-2019-5224P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.…5.5
- CVE-2019-5225P30, Mate 20, P30 Pro smartphones with software of versions …7.8
- CVE-2019-5227P30, P30 Pro, Mate 20 smartphones with software of versions …5.5
- CVE-2019-5228Certain detection module of P30, P30 Pro, Honor V20 smartpho…7.8
- CVE-2019-5229P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.…6.2
- CVE-2019-5230P20 Pro, P20, Mate RS smartphones with versions earlier than…5.5
- CVE-2019-5231P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.…4.6
- CVE-2019-5232There is a use of insufficiently random values vulnerability…7.5
Are you affected by CVE-2019-5226?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
