CVE Database
/

CVE-2019-5307

Back to search

CVE-2019-5307

Published: Jun 4, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Pro versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), are exposed to a message replay vulnerability. For the sake of better compatibility, these devices implement a less strict check on the NAS message sequence number (SN), specifically NAS COUNT. As a result, an attacker can construct a rogue base station and replay the GUTI reallocation command message in certain conditions to tamper with GUTIs, or replay the Identity request message to obtain IMSIs. (Vulnerability ID: HWPSIRT-2019-04107)

VendorProductVersions

Huawei

P30,P30 Pro

affected
The versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1)
affected
The versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now