Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2019-5250 |
CWE-ID | CWE-285 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
Huawei Mate 20 Pro Client/Desktop applications / Multimedia software |
Vendor | Huawei |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU23411
Risk: Low
CVSSv3.1: 2.8 [CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2019-5250
CWE-ID:
CWE-285 - Improper Authorization
Exploit availability: No
DescriptionThe vulnerability allows an attacker to bypass authorization checks.
The vulnerability exists due to the affected software does not properly restrict certain operation of certain privilege. An attacker with physical access to the device can trick the victim to install a malicious application before the user turns on student mode function and bypass the limit of student mode function.
MitigationInstall updates from vendor's website.
Vulnerable software versionsHuawei Mate 20 Pro: before 9.1.0.135
External linkshttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191204-02-smartphone-en
Q & A
Can this vulnerability be exploited remotely?
No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.