SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-5235

Some Huawei smart phones have a null pointer dereference vulnerability.

MEDIUM 5.3EPSS 0.92%

Does this matter?

Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.

Description

Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
0.92% probability · 58th percentile
CISA KEV
Not listed
Weakness
CWE-476
Affected
huawei/alp-al00b firmware · huawei/alp-tl00b firmware · huawei/bla-al00b firmware · huawei/bla-tl00b firmware · huawei/charlotte-al00a firmware · huawei/charlotte-tl00b firmware · huawei/columbia-al10b firmware · huawei/columbia-al10i firmware · huawei/columbia-l29d firmware · huawei/columbia-tl00d firmware · huawei/elle-al00b firmware · huawei/elle-tl00b firmware · huawei/emily-al00a firmware · huawei/emily-tl00b firmware · huawei/ever-al00b firmware · huawei/ever-l29b firmware · huawei/harry-al00c firmware · huawei/harry-al10b firmware · huawei/harry-tl00c firmware · huawei/hima-al00b firmware · +30 more
Source
psirt@huawei.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.