There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band.
References
Link | Resource |
---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191106-01-band-en | Vendor Advisory |
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191106-01-band-en | Vendor Advisory |
Configurations
History
21 Nov 2024, 04:44
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191106-01-band-en - Vendor Advisory |
Information
Published : 2019-11-29 20:15
Updated : 2024-11-21 04:44
NVD link : CVE-2019-5218
Mitre link : CVE-2019-5218
CVE.ORG link : CVE-2019-5218
JSON object : View
Products Affected
huawei
- band_3
- band_3_firmware
- band_2
- band_2_firmware
CWE
CWE-287
Improper Authentication