CVE-2019-5235
Last modified
CVE-2019-5235 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Alp-Al00b Firmware | 8.0.0.153\(c00\) |
| Huawei | Alp-Tl00b Firmware | 8.0.0.129\(sp2c01\) |
| Huawei | Bla-Al00b Firmware | 8.0.0.129\(sp2c786\) |
| Huawei | Bla-Al00b Firmware | 8.0.0.153\(c00\) |
| Huawei | Bla-Tl00b Firmware | 8.0.0.129\(sp2c01\) |
| Huawei | Charlotte-Al00a Firmware | 8.1.0.176\(c00\) |
| Huawei | Charlotte-Tl00b Firmware | 8.1.0.176\(c01\) |
| Huawei | Columbia-Al10b Firmware | 8.1.0.163\(c00\) |
| Huawei | Columbia-Al10i Firmware | 8.1.0.150\(c675custc675d2\) |
| Huawei | Columbia-L29d Firmware | 8.1.0.146\(c461\) |
| Huawei | Columbia-L29d Firmware | 8.1.0.148\(c185\) |
| Huawei | Columbia-L29d Firmware | 8.1.0.151\(c10\) |
| Huawei | Columbia-L29d Firmware | 8.1.0.151\(c432\) |
| Huawei | Columbia-Tl00d Firmware | 8.1.0.186\(c01gt\) |
| Huawei | Elle-Al00b Firmware | 9.1.0.162\(c00e160r2p1\) |
| Huawei | Elle-Tl00b Firmware | 9.1.0.162\(c01e160r2p1\) |
| Huawei | Emily-Al00a Firmware | 8.1.0.190\(c00\) |
| Huawei | Emily-Tl00b Firmware | 8.1.0.175\(c01\) |
| Huawei | Ever-Al00b Firmware | 9.0.0.195\(c00e195r2p1\) |
| Huawei | Ever-L29b Firmware | 9.0.0.206\(c185e3r3p1\) |
| Huawei | Ever-L29b Firmware | 9.0.0.207\(c636e3r2p1\) |
| Huawei | Ever-L29b Firmware | 9.0.0.208\(c432e3r1p12\) |
| Huawei | Harry-Al00c Firmware | 9.1.0.206\(c00e205r3p1\) |
| Huawei | Harry-Al10b Firmware | All versions |
| Huawei | Harry-Al10b Firmware | 9.1.0.206\(c00e205r3p1\) |
| Huawei | Harry-Tl00c Firmware | 9.0.1.162\(c01e160r2p3\) |
| Huawei | Hima-Al00b Firmware | 9.0.0.200\(c00e200r2p1\) |
| Huawei | Jackman-L21 Firmware | 8.2.0.160\(c185\) |
| Huawei | Jackman-L22 Firmware | 8.2.0.156\(c636r2p2\) |
| Huawei | Jackman-L23 Firmware | 8.2.0.152\(c45custc45d1\) |
| Huawei | Jackman-L23 Firmware | 8.2.0.162\(c605\) |
| Huawei | Johnson-Al00ic Firmware | 8.2.0.161\(c675custc675d1\) |
| Huawei | Johnson-Al10c Firmware | 8.2.0.165\(c00r1p16\) |
| Huawei | Johnson-L21c Firmware | 8.2.0.130\(c461r1p1\) |
| Huawei | Johnson-L21c Firmware | 8.2.0.131\(c10r2p2\) |
| Huawei | Johnson-L21c Firmware | 8.2.0.136\(c432custc432d1\) |
| Huawei | Johnson-L21d Firmware | 8.2.0.101\(c10custc10d1\) |
| Huawei | Johnson-L21d Firmware | 8.2.0.101\(c432custc432d1\) |
| Huawei | Johnson-L21d Firmware | 8.2.0.131\(c55custc55d1\) |
| Huawei | Johnson-L22c Firmware | 8.2.0.105\(c185r1p1\) |
| Huawei | Johnson-L22c Firmware | 8.2.0.107\(c636r2p1\) |
| Huawei | Johnson-L22d Firmware | 8.2.0.105\(c185r2p1\) |
| Huawei | Johnson-L22d Firmware | 8.2.0.107\(c636r2p1\) |
| Huawei | Johnson-L23c Firmware | 8.2.0.130\(c636custc636d2\) |
| Huawei | Johnson-L23c Firmware | 8.2.0.133\(c605custc605d1\) |
| Huawei | Johnson-L42ic Firmware | 8.2.0.155\(c675r2p1\) |
| Huawei | Johnson-L42ie Firmware | 8.2.0.155\(c675r2p1\) |
| Huawei | Johnson-L42if Firmware | 8.2.0.155\(c675r2p1\) |
| Huawei | Johnson-Tl00d Firmware | 8.2.0.100\(c541custc541d1\) |
| Huawei | Johnson-Tl00d Firmware | 8.2.0.165\(c01r1p16\) |
Showing 50 of 66 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5235?
How severe is CVE-2019-5235?
How do I fix CVE-2019-5235?
Are you affected by CVE-2019-5235?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
