Man-in-the-Middle (MitM) attack in P30 Pro and P30 - CVE-2019-5215

 

Man-in-the-Middle (MitM) attack in P30 Pro and P30 - CVE-2019-5215

Published: September 30, 2019


Vulnerability identifier: #VU21449
CSH Severity: Low
CVSS v4: 7.6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5215
CWE-ID: CWE-300
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows remote attacker to perform a man-in-the-middle attack.

The vulnerability exists due to the affected software does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint. When users establish connection and transfer data through Huawei Share, an attacker at adjacent network can sniffer, spoof and do a series of operations to intrude the Huawei Share connection and launch a man-in-the-middle attack to obtain and tamper the data.

Affected software

P30 Pro
P30

How to mitigate CVE-2019-5215

Install updates from vendor's website.

P30 Pro - update to 9.1.0.162
P30 - update to 9.1.0.162

External References

Related Security Bulletins