CVE-2019-5227 describes a version downgrade vulnerability affecting specific Huawei P30, P30 Pro, and Mate 20 smartphone models, as well as the HiSuite software. The flaw stems from insufficient validation of upgrade packages, allowing an attacker to revert the device's software to an older, potentially less secure version. With a CVSS score of 5.5 (Medium), this vulnerability requires user interaction (UI:R) and local access (AV:L) to exploit, but could lead to high integrity impacts (I:H) by enabling the installation of compromised or vulnerable firmware. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< elle-al00b_9.1.0.193\(c00e190r2p1\)CPE matchmatch criteria | cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:* | ||
< vogue-al00a_9.1.0.193\(c00e190r2p1\)CPE matchmatch criteria | cpe:2.3:o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:* | ||
< hima-al00b_9.1.0.135\(c00e133r2p1\)CPE matchmatch criteria | cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:* | ||
< 9.1.0.305CPE matchmatch criteria | cpe:2.3:o:huawei:hisuite_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.