VulnerabilityModified
CVE-2019-19398
M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability.
CRITICAL 9.8EPSS 1.43%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validation logic is incorrect, an attacker can exploit this vulnerability to modify the memory of the device by doing a series of operations. Successful exploit may lead to malicious code execution.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.43% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- huawei/m5 lite 10 firmware
- Source
- psirt@huawei.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.