CVE-2019-5292
Last modified
CVE-2019-5292 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. Honor 10 Lite, Honor 8A, Huawei Y6 mobile phones with the versions before 9.1.0.217(C00E215R3P1), the versions before 9.1.0.205(C00E97R1P9), the versions before 9.1.0.205(C00E97R2P2) have an information leak vulnerability. Due to improper function error records of some module, an attacker with the access permission may exploit the vulnerability to obtain some information.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Honor 10 Lite, Honor 8A, Huawei Y6 mobile phones with the versions before 9.1.0.217(C00E215R3P1), the versions before 9.1.0.205(C00E97R1P9), the versions before 9.1.0.205(C00E97R2P2) have an information leak vulnerability. Due to improper function error records of some module, an attacker with the access permission may exploit the vulnerability to obtain some information.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Honor 10 Lite Firmware | < 9.1.0.217\(c00e215r3p1\) |
| Huawei | Honor 8a Firmware | < 9.1.0.205\(c00e97r1p9\) |
| Huawei | Huawei Y6 Firmware | < 9.1.0.205\(c00e97r2p2\) |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5292?
How severe is CVE-2019-5292?
How do I fix CVE-2019-5292?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-5286There is a reflection XSS vulnerability in the HedEx product…
- CVE-2019-5287P30 smart phones with versions earlier than ELLE-AL00B 9.1.0…7.8
- CVE-2019-5288P30 smart phones with versions earlier than ELLE-AL00B 9.1.0…7.8
- CVE-2019-5289Gauss100 OLTP database in ManageOne with versions of 6.5.0 h…7.5
- CVE-2019-5290Huawei S5700 and S6700 have a DoS security vulnerability. At…6.5
- CVE-2019-5291Some Huawei products have an insufficient verification of da…5.9
- CVE-2019-5293Some Huawei products have a memory leak vulnerability when h…6.5
- CVE-2019-5294There is an out of bound read vulnerability in some Huawei p…7.5
- CVE-2019-5295Huawei Honor V10 smartphones versions earlier than Berkeley-…
- CVE-2019-5296Mate20 Huawei smartphones versions earlier than HMA-AL00C00B…
- CVE-2019-5297Emily-L29C Huawei phones versions earlier than 9.0.0.159 (C1…
- CVE-2019-5298There is an improper authentication vulnerability in some Hu…
Are you affected by CVE-2019-5292?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
