CVE-2019-5271

Published: Nov 29, 2019 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2019-14876 Aliases: GSD-2019-5271
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 5,4
Attack Vector: adjacent_network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: none
MEDIUM 4,8
Access Vector: adjacent_network
Access Complexity: low
Authentication: none
Confidentiality: partial
Integrity: partial
Availability: none

Description

AI Translation Available

There is an information leak vulnerability in Huawei smart speaker Myna. When the smart speaker is paired with the cloud through Wi-Fi, the speaker incorrectly processes some data. Attackers can exploit this vulnerability to read and modify specific configurations of speakers through a series of operations.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0008
Percentile
0,2th
Updated

EPSS Score Trend (Last 91 Days)

Operating System

Myna Firmware by Huawei

cpe:2.3:o:huawei:myna_firmware:9.0.1.10\(h100sp5c00\):*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Myna Firmware by Huawei

cpe:2.3:o:huawei:myna_firmware:9.0.1.10\(h100sp8c00\):*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Myna Firmware by Huawei

cpe:2.3:o:huawei:myna_firmware:9.0.1.9\(h100sp6c00\):*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Myna Firmware by Huawei

cpe:2.3:o:huawei:myna_firmware:9.0.1.10\(h100sp12c00\):*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Myna Firmware by Huawei

cpe:2.3:o:huawei:myna_firmware:9.0.1.10\(h100sp10c00\):*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Myna Firmware by Huawei

cpe:2.3:o:huawei:myna_firmware:9.0.1.10\(h100sp11c00\):*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191127-01-myna-…
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191127-01-myna-…