CVE-2019-5302 describes two denial of service vulnerabilities in various Huawei smartphones, including models from the Mate, P, Y, and Honor series, running specific firmware versions. An attacker can exploit these vulnerabilities by sending specially crafted TD-SCDMA messages from a rogue base station. Due to insufficient input validation, successful exploitation can cause the affected device to behave abnormally, leading to a denial of service. The vulnerability has a CVSS v3.1 score of 5.3 (Medium), indicating a network-adjacent attack vector with high attack complexity, requiring no user interaction. The potential impact is a high availability loss, as the device may become abnormal. There is no evidence of active exploitation (KEV: No), nor are there any public exploit modules available (Metasploit, Nuclei, ExploitDB: None). Community discussion and media coverage for this CVE are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.1.0.333\(c00e333r2p1t8\)CPE matchmatch criteria | cpe:2.3:o:huawei:alp-al00b_firmware:*:*:*:*:*:*:*:* | ||
< 9.1.0.300\(c432e4r1p9t8\)CPE matchmatch criteria | cpe:2.3:o:huawei:alp-l09_firmware:*:*:*:*:*:*:*:* | ||
< 9.1.0.315\(c636e5r1p13t8\)CPE matchmatch criteria | cpe:2.3:o:huawei:alp-l29_firmware:*:*:*:*:*:*:*:* | ||
< 9.1.0.321\(c636e4r1p14t8\)CPE matchmatch criteria | cpe:2.3:o:huawei:bla-l29c_firmware:*:*:*:*:*:*:*:* | ||
< 9.1.0.330\(c432e6r1p12t8\)CPE matchmatch criteria | cpe:2.3:o:huawei:bla-l29c_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.