CVE-2019-5213

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
12/11/2019
Last modified:
15/11/2019

Description

Honor play smartphones with versions earlier than Cornell-AL00A 9.1.0.321(C00E320R1P1T8) have an insufficient authentication vulnerability. The system has a logic judge error under certain scenario. Successful exploit could allow the attacker to modify the alarm clock settings after a serious of uncommon operations without unlock the screen lock.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:honor_play_firmware:*:*:*:*:*:*:*:* cornell-al00a_9.1.0.321\(c00e320r1p1t8\) (excluding)
cpe:2.3:h:huawei:honor_play:-:*:*:*:*:*:*:*