CVE-2019-5218

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
29/11/2019
Last modified:
16/12/2019

Description

There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:band_2_firmware:*:*:*:*:*:*:*:* eris-b19\/eris-b29_1.2.53 (excluding)
cpe:2.3:h:huawei:band_2:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:band_3_firmware:*:*:*:*:*:*:*:* nyx-b10hn_1.5.53 (excluding)
cpe:2.3:h:huawei:band_3:-:*:*:*:*:*:*:*