ID

VAR-201911-0828


CVE

CVE-2019-5218


TITLE

Huawei Band 2 and Honor Band 3 Authentication vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2019-013083

DESCRIPTION

There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band. Huawei Band 2 and Honor Band 3 Contains an authentication vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Huawei Bracelet 2 and Honor Bracelet 3 are both smart bracelets from China's Huawei. Huawei Band 2 Eris-B19 / Eris-B29 versions prior to 1.2.53 and Honor Band 3 NYX-B10HN versions prior to 1.5.53 have security vulnerabilities, which originated from the program I can fully authenticate

Trust: 2.16

sources: NVD: CVE-2019-5218 // JVNDB: JVNDB-2019-013083 // CNVD: CNVD-2019-41254

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-41254

AFFECTED PRODUCTS

vendor:huaweimodel:band 2scope:eqversion: -

Trust: 1.2

vendor:huaweimodel:band 3scope:eqversion: -

Trust: 1.2

vendor:huaweimodel:band 3scope:ltversion:nyx-b10hn_1.5.53

Trust: 1.0

vendor:huaweimodel:band 2scope:ltversion:eris-b19\/eris-b29_1.2.53

Trust: 1.0

vendor:huaweimodel:honor band 3scope: - version: -

Trust: 0.8

vendor:huaweimodel:band 2scope: - version: -

Trust: 0.8

vendor:huaweimodel:bracelet <eris-b19 eris-b29scope:eqversion:2/1.2.53

Trust: 0.6

vendor:huaweimodel:bracelet eris-b19 eris-b29 || glory bracelet nyx-b10hnscope:eqversion:2/3<1.2.53

Trust: 0.6

vendor:huaweimodel:honor band <nyx-b10hnscope:eqversion:31.5.53

Trust: 0.6

sources: CNVD: CNVD-2019-41254 // JVNDB: JVNDB-2019-013083 // CNNVD: CNNVD-201911-354 // NVD: CVE-2019-5218

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-5218
value: HIGH

Trust: 1.0

NVD: CVE-2019-5218
value: HIGH

Trust: 0.8

CNVD: CNVD-2019-41254
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201911-354
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2019-5218
severity: MEDIUM
baseScore: 5.8
vectorString: AV:A/AC:L/AU:N/C:P/I:P/A:P
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 6.5
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-41254
severity: MEDIUM
baseScore: 6.8
vectorString: AV:A/AC:H/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.2
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2019-5218
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2019-5218
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: ADJACENT NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2019-41254 // JVNDB: JVNDB-2019-013083 // CNNVD: CNNVD-201911-354 // NVD: CVE-2019-5218

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.8

sources: JVNDB: JVNDB-2019-013083 // NVD: CVE-2019-5218

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-201911-354

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201911-354

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-013083

PATCH

title:huawei-sa-20191106-01-bandurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191106-01-band-en

Trust: 0.8

title:Patch for Insufficient certification of multiple Huawei bracelet productsurl:https://www.cnvd.org.cn/patchInfo/show/190789

Trust: 0.6

title:Huawei Huawei bracelet 2 And glory bracelet 3 Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=105195

Trust: 0.6

sources: CNVD: CNVD-2019-41254 // JVNDB: JVNDB-2019-013083 // CNNVD: CNNVD-201911-354

EXTERNAL IDS

db:NVDid:CVE-2019-5218

Trust: 3.0

db:JVNDBid:JVNDB-2019-013083

Trust: 0.8

db:CNVDid:CNVD-2019-41254

Trust: 0.6

db:CNNVDid:CNNVD-201911-354

Trust: 0.6

sources: CNVD: CNVD-2019-41254 // JVNDB: JVNDB-2019-013083 // CNNVD: CNNVD-201911-354 // NVD: CVE-2019-5218

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191106-01-band-en

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2019-5218

Trust: 1.4

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20191106-01-band-cn

Trust: 1.2

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-5218

Trust: 0.8

sources: CNVD: CNVD-2019-41254 // JVNDB: JVNDB-2019-013083 // CNNVD: CNNVD-201911-354 // NVD: CVE-2019-5218

SOURCES

db:CNVDid:CNVD-2019-41254
db:JVNDBid:JVNDB-2019-013083
db:CNNVDid:CNNVD-201911-354
db:NVDid:CVE-2019-5218

LAST UPDATE DATE

2024-11-23T23:01:38.939000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-41254date:2019-11-19T00:00:00
db:JVNDBid:JVNDB-2019-013083date:2019-12-19T00:00:00
db:CNNVDid:CNNVD-201911-354date:2019-12-17T00:00:00
db:NVDid:CVE-2019-5218date:2024-11-21T04:44:32.337

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-41254date:2019-11-19T00:00:00
db:JVNDBid:JVNDB-2019-013083date:2019-12-19T00:00:00
db:CNNVDid:CNNVD-201911-354date:2019-11-06T00:00:00
db:NVDid:CVE-2019-5218date:2019-11-29T20:15:11.020