#VU23618 Information disclosure in Huawei Client/Desktop applications


Published: 2019-12-16

Vulnerability identifier: #VU23618

Vulnerability risk: Low

CVSSv3.1: 2.1 [CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-5264

CWE-ID: CWE-200

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Huawei Mate 10
Client/Desktop applications / Multimedia software
Huawei Mate 10 Pro
Client/Desktop applications / Multimedia software
Huawei Honor V10
Client/Desktop applications / Multimedia software
Changxiang 7S
Client/Desktop applications / Multimedia software
Huawei P-smart
Client/Desktop applications / Multimedia software
Changxiang 8 Plus
Client/Desktop applications / Multimedia software
Huawei Y9 2018
Client/Desktop applications / Multimedia software
Huawei Honor 9 Lite
Client/Desktop applications / Multimedia software
Huawei Honor 9i
Client/Desktop applications / Multimedia software
Huawei Mate 9
Client/Desktop applications / Multimedia software

Vendor: Huawei

Description

The vulnerability allows an attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected software does not properly handle certain information of application locked by applock in a rare condition. An attacker with physical access to the device can gain unauthorized access to sensitive information on the system.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Huawei Mate 10: All versions

Huawei Mate 10 Pro: All versions

Huawei Honor V10: All versions

Changxiang 7S: All versions

Huawei P-smart: All versions

Changxiang 8 Plus: All versions

Huawei Y9 2018: All versions

Huawei Honor 9 Lite: All versions

Huawei Honor 9i: All versions

Huawei Mate 9: All versions


External links
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191211-01-smartphone-en


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability