CVE-2019-5251
Estado: ModificadaMedia (5.5)—
There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.84%
- Percentil entre todas las CVEs puntuadas: 56
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (9)
CWE
- CWE-22
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-5251",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "psirt@huawei.com",
"affectedData": [
{
"vendor": "n/a",
"product": "Honor V10;P30;Mate 20;Honor 9 Lite;Honor 9i;M6;P30 Pro;Honor 20s",
"versions": [
{
"status": "affected",
"version": "Versions earlier than 9.1.0.333(C00E333R2P1T8)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.226(C00E220R2P1)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.130(C00E115R2P8T8)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.139(C00E133R3P1)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.130(C00E112R2P10T8)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.143(C636E5R1P5T8)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.120(C00E113R1P6T8)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.1.150(C00E150R1P150)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.226(C00E210R2P1)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.1.132(C00E131R6P1)"
}
]
}
]
}
],
"published": "2019-12-13T15:15:11.317",
"references": [
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191204-03-smartphone-en",
"tags": [
"Vendor Advisory"
],
"source": "psirt@huawei.com"
},
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191204-03-smartphone-en",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad de salto de ruta en varios teléfonos inteligentes Huawei. El sistema no comprueba de forma suficiente ciertos nombres de ruta de la aplicación. Un atacante podría engañar al usuario para que instale, realice una copia de seguridad y restaure una aplicación maliciosa. Una explotación con éxito podría causar una divulgación de información."
}
],
"lastModified": "2026-06-17T02:37:22.430",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:honor_v10_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B394D790-9589-4FC3-8B51-47B9F6E241D2",
"versionEndExcluding": "9.1.0.333\\(c00e333r2p1t8\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:honor_v10:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "592CF37A-83FA-4C85-B5E7-1DB2297A77A0"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "76BF8190-0F8E-4BEF-81C6-FE409F6B812A",
"versionEndExcluding": "9.1.0.226\\(c00e220r2p1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "21EE286C-8111-4F59-8CF1-13C68EA76B21"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:enjoy_7s_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29CD79B3-14E0-44A4-B9DE-4C4A47449626",
"versionEndExcluding": "9.1.0.130\\(c00e115r2p8t8\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:enjoy_7s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "40688207-579D-444D-A594-54E65069B6A3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B9BE6DA3-8840-4B23-8F78-632112A2B039",
"versionEndExcluding": "9.1.0.139\\(c00e133r3p1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:mate_20:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B5322963-9375-4E4E-8119-895C224003AE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:honor_9_lite_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6154A71C-59D9-47C0-B7CA-AC837CB70E32",
"versionEndExcluding": "9.1.0.143\\(c636e5r1p5t8\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:honor_9_lite:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E571CDA8-577E-4165-A960-DAD978FD23BC"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:honor_9i_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5DA66B4F-B5D6-485B-A741-1D08C03957E0",
"versionEndExcluding": "9.1.0.120\\(c00e113r1p6t8\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:honor_9i:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F931151C-4D0A-44D1-9417-B467F7E148A2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:m6_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FC9664F-3422-4630-B917-326BDC4AF0BE",
"versionEndExcluding": "9.1.1.150\\(c00e150r1p150\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:m6:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "996B603A-E8F8-408D-A204-BB0638498F9E"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B40B07F3-0A6C-4102-976F-2E787311AA12",
"versionEndExcluding": "9.1.0.226\\(c00e210r2p1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:p30_pro:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6DB671DB-CB5B-46E0-B221-722D051184DE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:honor_20s_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BEBB5CD-2714-4761-A0C7-D97D24D267B6",
"versionEndExcluding": "9.1.1.132\\(c00e131r6p1\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:honor_20s:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C1442135-75BB-4C2C-8BBF-354CB0978489"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:huawei:honor_9_lite_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD9024A1-9F5A-4953-AE7C-6AB9926C0BBB",
"versionEndExcluding": "9.1.0.130\\(c00e112r2p10t8\\)"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:honor_9_lite:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E571CDA8-577E-4165-A960-DAD978FD23BC"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@huawei.com"
}