CVE-2019-5302
5.3
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.6 / Impact: 3.6
Source: NVD
Description
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1 out of 2 vulnerabilities. Different than CVE-2020-5303. Affected products are: ALP-AL00B: earlier than 9.1.0.333(C00E333R2P1T8) ALP-L09: earlier than 9.1.0.300(C432E4R1P9T8) ALP-L29: earlier than 9.1.0.315(C636E5R1P13T8) BLA-L29C: earlier than 9.1.0.321(C636E4R1P14T8), earlier than 9.1.0.330(C432E6R1P12T8), earlier than 9.1.0.302(C635E4R1P13T8) Berkeley-AL20: earlier than 9.1.0.333(C00E333R2P1T8) Berkeley-L09: earlier than 9.1.0.350(C10E3R1P14T8), earlier than 9.1.0.351(C432E5R1P13T8), earlier than 9.1.0.350(C636E4R1P13T8) Charlotte-L09C: earlier than 9.1.0.311(C185E4R1P11T8), earlier than 9.1.0.345(C432E8R1P11T8) Charlotte-L29C: earlier than 9.1.0.325(C185E4R1P11T8), earlier than 9.1.0.335(C636E3R1P13T8), earlier than 9.1.0.345(C432E8R1P11T8), earlier than 9.1.0.336(C605E3R1P12T8) Columbia-AL10B: earlier than 9.1.0.333(C00E333R1P1T8) Columbia-L29D: earlier than 9.1.0.350(C461E3R1P11T8), earlier than 9.1.0.350(C185E3R1P12T8), earlier than 9.1.0.350(C10E5R1P14T8), earlier than 9.1.0.351(C432E5R1P13T8) Cornell-AL00A: earlier than 9.1.0.333(C00E333R1P1T8) Cornell-L29A: earlier than 9.1.0.328(C185E1R1P9T8), earlier than 9.1.0.328(C432E1R1P9T8), earlier than 9.1.0.330(C461E1R1P9T8), earlier than 9.1.0.328(C636E2R1P12T8) Emily-L09C: earlier than 9.1.0.336(C605E4R1P12T8), earlier than 9.1.0.311(C185E2R1P12T8), earlier than 9.1.0.345(C432E10R1P12T8) Emily-L29C: earlier than 9.1.0.311(C605E2R1P12T8), earlier than 9.1.0.311(C636E7R1P13T8), earlier than 9.1.0.311(C432E7R1P11T8) Ever-L29B: earlier than 9.1.0.311(C185E3R3P1), earlier than 9.1.0.310(C636E3R2P1), earlier than 9.1.0.310(C432E3R1P12) HUAWEI Mate 20: earlier than 9.1.0.131(C00E131R3P1) HUAWEI Mate 20 Pro: earlier than 9.1.0.310(C185E10R2P1) HUAWEI Mate 20 RS: earlier than 9.1.0.135(C786E133R3P1) HUAWEI Mate 20 X: earlier than 9.1.0.135(C00E133R2P1) HUAWEI P20: earlier than 9.1.0.333(C00E333R1P1T8) HUAWEI P20 Pro: earlier than 9.1.0.333(C00E333R1P1T8) HUAWEI P30: earlier than 9.1.0.193 HUAWEI P30 Pro: earlier than 9.1.0.186(C00E180R2P1) HUAWEI Y9 2019: earlier than 9.1.0.220(C605E3R1P1T8) HUAWEI nova lite 3: earlier than 9.1.0.305(C635E8R2P2) Honor 10 Lite: earlier than 9.1.0.283(C605E8R2P2) Honor 8X: earlier than 9.1.0.221(C461E2R1P1T8) Honor View 20: earlier than 9.1.0.238(C432E1R3P1) Jackman-L22: earlier than 9.1.0.247(C636E2R4P1T8) Paris-L21B: earlier than 9.1.0.331(C432E1R1P2T8) Paris-L21MEB: earlier than 9.1.0.331(C185E4R1P3T8) Paris-L29B: earlier than 9.1.0.331(C636E1R1P3T8) Sydney-AL00: earlier than 9.1.0.212(C00E62R1P7T8) Sydney-L21: earlier than 9.1.0.215(C432E1R1P1T8), earlier than 9.1.0.213(C185E1R1P1T8) Sydney-L21BR: earlier than 9.1.0.213(C185E1R1P2T8) Sydney-L22: earlier than 9.1.0.258(C636E1R1P1T8) Sydney-L22BR: earlier than 9.1.0.258(C636E1R1P1T8) SydneyM-AL00: earlier than 9.1.0.228(C00E78R1P7T8) SydneyM-L01: earlier than 9.1.0.215(C782E2R1P1T8), earlier than 9.1.0.213(C185E1R1P1T8), earlier than 9.1.0.270(C432E3R1P1T8) SydneyM-L03: earlier than 9.1.0.217(C605E1R1P1T8) SydneyM-L21: earlier than 9.1.0.221(C461E1R1P1T8), earlier than 9.1.0.215(C432E4R1P1T8) SydneyM-L22: earlier than 9.1.0.259(C185E1R1P2T8), earlier than 9.1.0.220(C635E1R1P2T8), earlier than 9.1.0.216(C569E1R1P1T8) SydneyM-L23: earlier than 9.1.0.226(C605E2R1P1T8) Yale-L21A: earlier than 9.1.0.154(C432E2R3P2), earlier than 9.1.0.154(C461E2R2P1), earlier than 9.1.0.154(C636E2R2P1) Honor 20: earlier than 9.1.0.152(C00E150R5P1) Honor Magic2: earlier than 10.0.0.187 Honor V20: earlier than 9.1.0.234(C00E234R4P3)
Affected (75)
Products: Huawei: Alp Al00b Firmware, Alp L09 Firmware, Alp L29 Firmware, Bla L29c Firmware, Berkeley Al20 Firmware, Berkeley L09 Firmware, Charlotte L09c Firmware, Charlotte L29c Firmware, Columbia Al10b Firmware, Columbia L29d Firmware, Cornell Al00a Firmware, Cornell L29a Firmware, Emily L09c Firmware, Emily L29c Firmware, Ever L29b Firmware, Mate 20 Firmware, Mate 20 Pro Firmware, Mate 20 Rs Firmware, Mate 20 X Firmware, P20 Firmware, P20 Pro Firmware, P30 Firmware, P30 Pro Firmware, Y9 2019 Firmware, Nova Lite 3 Firmware, Honor 10 Lite Firmware, Honor 8x Firmware, Honor View 20 Firmware, Jackman L22 Firmware, Paris L21b Firmware, Paris L21meb Firmware, Paris L29b Firmware, Sydney Al00 Firmware, Sydney L21 Firmware, Sydney L21br Firmware, Sydney L22 Firmware, Sydney L22br Firmware, Sydneym Al00 Firmware, Sydneym L01 Firmware, Sydneym L03 Firmware, Sydneym L21 Firmware, Sydneym L22 Firmware, Sydneym L23 Firmware, Yale L21a Firmware, Honor 20 Firmware, Honor Magic2 Firmware, Honor V20 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.333\(c00e333r2p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Alp Al00b | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.300\(c432e4r1p9t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Alp L09 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.315\(c636e5r1p13t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Alp L29 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.321\(c636e4r1p14t8\) |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.330\(c432e6r1p12t8\) |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.302\(c635e4r1p13t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Bla L29c | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.333\(c00e333r2p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Berkeley Al20 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.350\(c10e3r1p14t8\) |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.351\(c432e5r1p13t8\) |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.350\(c636e4r1p13t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Berkeley L09 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.311\(c185e4r1p11t8\) |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.345\(c432e8r1p11t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Charlotte L09c | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.325\(c185e4r1p11t8\) |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.335\(c636e3r1p13t8\) |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.345\(c432e8r1p11t8\) |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.336\(c605e3r1p12t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Charlotte L29c | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.333\(c00e333r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Columbia Al10b | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.350\(c461e3r1p11t8\) |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.350\(c185e3r1p12t8\) |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.350\(c10e5r1p14t8\) |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.351\(c432e5r1p13t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Columbia L29d | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.333\(c00e333r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Cornell Al00a | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.328\(c185e1r1p9t8\) |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.328\(c432e1r1p9t8\) |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.330\(c461e1r1p9t8\) |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.328\(c636e2r1p12t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Cornell L29a | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.336\(c605e4r1p12t8\) |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.311\(c185e2r1p12t8\) |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.345\(c432e10r1p12t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Emily L09c | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.311\(c605e2r1p12t8\) |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.311\(c636e7r1p13t8\) |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.311\(c432e7r1p11t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Emily L29c | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.311\(c185e3r3p1\) |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.310\(c636e3r2p1\) |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.310\(c432e3r1p12\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Ever L29b | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.131\(c00e131r3p1\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Mate 20 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.310\(c185e10r2p1\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Mate 20 Pro | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.135\(c786e133r3p1\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Mate 20 Rs | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.135\(c00e133r2p1\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Mate 20 X | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.333\(c00e333r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei P20 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.333\(c00e333r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei P20 Pro | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.193 |
| Running on/with | Platform Versions |
|---|---|
Huawei P30 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.186\(c00e180r2p1\) |
| Running on/with | Platform Versions |
|---|---|
Huawei P30 Pro | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.220\(c605e3r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Y9 2019 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.305\(c635e8r2p2\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Nova Lite 3 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.283\(c605e8r2p2\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Honor 10 Lite | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.221\(c461e2r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Honor 8x | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.238\(c432e1r3p1\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Honor View 20 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.247\(c636e2r4p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Jackman L22 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.331\(c432e1r1p2t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Paris L21b | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.331\(c185e4r1p3t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Paris L21meb | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.331\(c636e1r1p3t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Paris L29b | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.212\(c00e62r1p7t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Sydney Al00 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.215\(c432e1r1p1t8\) |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.213\(c185e1r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Sydney L21 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.213\(c185e1r1p2t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Sydney L21br | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.258\(c636e1r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Sydney L22 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.258\(c636e1r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Sydney L22br | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.228\(c00e78r1p7t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Sydneym Al00 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.215\(c782e2r1p1t8\) |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.213\(c185e1r1p1t8\) |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.270\(c432e3r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Sydneym L01 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.217\(c605e1r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Sydneym L03 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.221\(c461e1r1p1t8\) |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.215\(c432e4r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Sydneym L21 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.259\(c185e1r1p2t8\) |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.220\(c635e1r1p2t8\) |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.216\(c569e1r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Sydneym L22 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.226\(c605e2r1p1t8\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Sydneym L23 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.154\(c432e2r3p2\) |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.154\(c461e2r2p1\) |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.154\(c636e2r2p1\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Yale L21a | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.152\(c00e150r5p1\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Honor 20 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.0.187 |
| Running on/with | Platform Versions |
|---|---|
Huawei Honor Magic2 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.1.0.234\(c00e234r4p3\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Honor V20 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.