CVE-2019-5260

Huawei smartphones HUAWEI Y9 2019 and Honor View 20 have a denial of service vulnerability. Due to insufficient input validation of specific value when parsing the messages, an attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices to exploit this vulnerability. Successful exploit may cause an infinite loop and the device to reboot.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:huawei:y9_2019_firmware:8.2.0.160\(c185r2p2\):*:*:*:*:*:*:*
cpe:2.3:o:huawei:y9_2019_firmware:8.2.0.162\(c605\):*:*:*:*:*:*:*
cpe:2.3:o:huawei:y9_2019_firmware:8.2.0.163\(c605\):*:*:*:*:*:*:*
cpe:2.3:h:huawei:y9_2019:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:huawei:view_20_firmware:9.0.1.169\(c636e1r4p1\):*:*:*:*:*:*:*
cpe:2.3:o:huawei:view_20_firmware:9.0.1.170\(c185e2r3p1\):*:*:*:*:*:*:*
cpe:2.3:o:huawei:view_20_firmware:9.0.1.170\(c432e1r3p1\):*:*:*:*:*:*:*
cpe:2.3:h:huawei:view_20:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-12-13 22:15

Updated : 2024-02-28 17:28


NVD link : CVE-2019-5260

Mitre link : CVE-2019-5260

CVE.ORG link : CVE-2019-5260


JSON object : View

Products Affected

huawei

  • y9_2019_firmware
  • view_20_firmware
  • y9_2019
  • view_20
CWE
CWE-20

Improper Input Validation