CVE-2019-5213

LOW

Honor play <Cornell-AL00A 9.1.0.321(C00E320R1P1T8) - Insufficient A...

Title source: llm
STIX 2.1

Description

Honor play smartphones with versions earlier than Cornell-AL00A 9.1.0.321(C00E320R1P1T8) have an insufficient authentication vulnerability. The system has a logic judge error under certain scenario. Successful exploit could allow the attacker to modify the alarm clock settings after a serious of uncommon operations without unlock the screen lock.

References (1)

Core 1

Scores

CVSS v3 2.4
EPSS 0.0005
EPSS Percentile 16.0%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-287
Status published
Products (1)
huawei/honor_play_firmware < cornell-al00a_9.1.0.321\(c00e320r1p1t8\)
Published Nov 12, 2019
Tracked Since Feb 18, 2026