CVE-2019-5252

low-risk
Published 2019-12-14

There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.

Do I need to act?

-
0.05% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
3
CVSS 3.5/10 Low
PHYSICAL / LOW complexity

Affected Products (6)

Enjoy 8 Plus Firmware
Y9 Firmware
Honor 8X Firmware
Honor 9 Lite Firmware
Y6 Pro Firmware

Affected Vendors

26
/ 100
low-risk
Severity 13/34 · Low
Exploitability 0/34 · Minimal
Exposure 13/34 · Low