← Back to CVE List
Vulnerability Intelligence Report

CVE-2019-5282

Bastet module of some Huawei smartphones with Versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Versions earlier than Emily-TL00B 9.0.0.182(C01E82R1P21), Versions earlier than Emily-L09C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.202(C185E2R1P12) have a double free vulnerability. An attacker tricks the user into installing a malicious application, which frees on the same memory address twice. Successful exploit could result in malicious code execution.

No Active Exploit Signals
CVSS Base Score
7.8
HIGH
EPSS Probability:0.79%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
huawei emily-al00a_firmware all
huawei emily-al00a all
huawei emily-tl00b_firmware all
huawei emily-tl00b all
huawei emily-l09c_firmware all
huawei emily-l09c all
huawei emily-l29c_firmware all
huawei emily-l29c all
huawei hima-l09ca_firmware all
huawei hima-l09ca all
huawei hima-l29ca_firmware all
huawei hima-l29ca all
huawei hima-l29c_firmware all
huawei hima-l29c all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.792%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHuawei Technologies · Vendor · China
Reserved2019-01-04T00:00:00
Published2019-11-13T13:28:07
Last Updated2024-08-04T19:54:51

LINK COPIED TO CLIPBOARD