CVE-2019-5210
Summary
| CVE | CVE-2019-5210 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-29 20:15:00 UTC |
| Updated | 2019-12-05 17:51:00 UTC |
| Description | Nova 5i pro and Nova 5 smartphones with versions earlier than 9.1.1.190(C00E190R6P2)and Versions earlier than 9.1.1.175(C00E170R3P2) have an improper validation of array index vulnerability. The system does not properly validate the input value before use it as an array index when processing certain image information. The attacker tricks the user into installing a malicious application, successful exploit could cause malicious code execution. |
Risk And Classification
Problem Types: CWE-129
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Nova 5 | - | All | All | All |
| Hardware | Huawei | Nova 5 | - | All | All | All |
| Hardware | Huawei | Nova 5i Pro | - | All | All | All |
| Hardware | Huawei | Nova 5i Pro | - | All | All | All |
| Operating System | Huawei | Nova 5i Pro Firmware | All | All | All | All |
| Operating System | Huawei | Nova 5i Pro Firmware | All | All | All | All |
| Operating System | Huawei | Nova 5 Firmware | All | All | All | All |
| Operating System | Huawei | Nova 5 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Improper Validation of Array Index Vulnerability in Several Smartphones | CONFIRM | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.