CVE-2019-5218
8.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band.
Affected (2)
Products: Huawei: Band 2 Firmware, Band 3 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before eris-b19\/eris-b29_1.2.53 |
| Running on/with | Platform Versions |
|---|---|
Huawei Band 2 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before nyx-b10hn_1.5.53 |
| Running on/with | Platform Versions |
|---|---|
Huawei Band 3 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.