ZeroHour

CVE-2019-5222

CVSS 3.0
5.5 medium
EPSS
<1%p48
Published
()
Modified
Description

There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 9.1.0.216(C00E214R2P1). The Secure Input does not properly limit certain system privilege. An attacker tricks the user to install a malicious application and successful exploit could result in information disclosure.

Vendors
huawei
Products
honor magic 2 firmware
Weakness
CWE-732
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.