CVE-2019-5246
Last modified
CVE-2019-5246 is a medium-severity vulnerability rated 6.2/10 on the CVSS scale. Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verification vulnerability. The system does not verify certain parameters sufficiently, an attacker should connect to the phone and gain high privilege to launch the attack. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Smartphones with software of ELLE-AL00B 9.1.0.109(C00E106R1P21), 9.1.0.113(C00E110R1P21), 9.1.0.125(C00E120R1P21), 9.1.0.135(C00E130R1P21), 9.1.0.153(C00E150R1P21), 9.1.0.155(C00E150R1P21), 9.1.0.162(C00E160R2P1) have an insufficient verification vulnerability. The system does not verify certain parameters sufficiently, an attacker should connect to the phone and gain high privilege to launch the attack. Successful exploit could cause DOS or malicious code execution.
Metrics
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Elle-Al00b Firmware | 9.1.0.109\(c00e106r1p21\) |
| Huawei | Elle-Al00b Firmware | 9.1.0.113\(c00e110r1p21\) |
| Huawei | Elle-Al00b Firmware | 9.1.0.125\(c00e120r1p21\) |
| Huawei | Elle-Al00b Firmware | 9.1.0.135\(c00e130r1p21\) |
| Huawei | Elle-Al00b Firmware | 9.1.0.153\(c00e150r1p21\) |
| Huawei | Elle-Al00b Firmware | 9.1.0.155\(c00e150r1p21\) |
| Huawei | Elle-Al00b Firmware | 9.1.0.162\(c00e160r2p1\) |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5246?
How severe is CVE-2019-5246?
How do I fix CVE-2019-5246?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-5239Huawei PCManager with the versions before 9.0.1.66 (Oversea)…
- CVE-2019-5241There is a privilege escalation vulnerability in Huawei PCMa…
- CVE-2019-5242There is a code execution vulnerability in Huawei PCManager …
- CVE-2019-5243There is a Clickjacking vulnerability in Huawei HG255s produ…
- CVE-2019-5244Mate 9 Pro Huawei smartphones earlier than LON-L29C 8.0.0.36…
- CVE-2019-5245HiSuite 9.1.0.300 versions and earlier contains a DLL hijack…
- CVE-2019-5247Huawei Atlas 300, Atlas 500 have a buffer overflow vulnerabi…5.5
- CVE-2019-5248CloudEngine 12800 has a DoS vulnerability. An attacker of a …7.4
- CVE-2019-5250Mate 20 Pro smartphones with versions earlier than 9.1.0.135…7.8
- CVE-2019-5251There is a path traversal vulnerability in several Huawei sm…5.5
- CVE-2019-5252There is an improper authentication vulnerability in Huawei …3.5
- CVE-2019-5253E5572-855 with versions earlier than 8.0.1.3(H335SP1C233) ha…5.9
Are you affected by CVE-2019-5246?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
