CVE-2019-5252
low-risk
Published 2019-12-14
There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.
Do I need to act?
-
0.05% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
3
CVSS 3.5/10
Low
PHYSICAL
/ LOW complexity
Affected Products (6)
Enjoy 8 Plus Firmware
Y9 Firmware
Honor 8X Firmware
Honor 9 Lite Firmware
Y6 Pro Firmware
Affected Vendors
References (2)
26
/ 100
low-risk
Severity
13/34 · Low
Exploitability
0/34 · Minimal
Exposure
13/34 · Low