ZeroHour

CVE-2019-5218

CVSS 3.1
8.8 high
EPSS
<1%p33
Published
()
Modified
Description

There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band.

Vendors
huawei
Products
band 2 firmware, band 3 firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.