Skip to content
Noroxi
CVE-2019-5302· NVD / CVE Program· CNA huawei

There are two denial of service vulnerabilities on some Huawei smartphones.

There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1 out of 2 vulnerabilities. Different than CVE-2020-5303. Affected products are: ALP-AL00B: earlier than 9.1.0.333(C00E333R2P1T8) ALP-L09: earlier than 9.1.0.300(C432E4R1P9T8) ALP-L29: earlier than 9.1.0.315(C636E5R1P13T8) BLA-L29C: earlier than 9.1.0.321(C636E4R1P14T8), earlier than 9.1.0.330(C432E6R1P12T8), earlier than 9.1.0.302(C635E4R1P13T8) Berkeley-AL20: earlier than 9.1.0.333(C00E333R2P1T8) Berkeley-L09: earlier than 9.1.0.350(C10E3R1P14T8), earlier than 9.1.0.351(C432E5R1P13T8), earlier than 9.1.0.350(C636E4R1P13T8) Charlotte-L09C: earlier than 9.1.0.311(C185E4R1P11T8), earlier than 9.1.0.345(C432E8R1P11T8) Charlotte-L29C: earlier than 9.1.0.325(C185E4R1P11T8), earlier than 9.1.0.335(C636E3R1P13T8), earlier than 9.1.0.345(C432E8R1P11T8), earlier than 9.1.0.336(C605E3R1P12T8) Columbia-AL10B: earlier than 9.1.0.333(C00E333R1P1T8) Columbia-L29D: earlier than 9.1.0.350(C461E3R1P11T8), earlier than 9.1.0.350(C185E3R1P12T8), earlier than 9.1.0.350(C10E5R1P14T8), earlier than 9.1.0.351(C432E5R1P13T8) Cornell-AL00A: earlier than 9.1.0.333(C00E333R1P1T8) Cornell-L29A: earlier than 9.1.0.328(C185E1R1P9T8), earlier than 9.1.0.328(C432E1R1P9T8), earlier than 9.1.0.330(C461E1R1P9T8), earlier than 9.1.0.328(C636E2R1P12T8) Emily-L09C: earlier than 9.1.0.336(C605E4R1P12T8), earlier than 9.1.0.311(C185E2R1P12T8), earlier than 9.1.0.345(C432E10R1P12T8) Emily-L29C: earlier than 9.1.0.311(C605E2R1P12T8), earlier than 9.1.0.311(C636E7R1P13T8), earlier than 9.1.0.311(C432E7R1P11T8) Ever-L29B: earlier than 9.1.0.311(C185E3R3P1), earlier than 9.1.0.310(C636E3R2P1), earlier than 9.1.0.310(C432E3R1P12) HUAWEI Mate 20: earlier than 9.1.0.131(C00E131R3P1) HUAWEI Mate 20 Pro: earlier than 9.1.0.310(C185E10R2P1) HUAWEI Mate 20 RS: earlier than 9.1.0.135(C786E133R3P1) HUAWEI Mate 20 X: earlier than 9.1.0.135(C00E133R2P1) HUAWEI P20: earlier than 9.1.0.333(C00E333R1P1T8) HUAWEI P20 Pro: earlier than 9.1.0.333(C00E333R1P1T8) HUAWEI P30: earlier than 9.1.0.193 HUAWEI P30 Pro: earlier than 9.1.0.186(C00E180R2P1) HUAWEI Y9 2019: earlier than 9.1.0.220(C605E3R1P1T8) HUAWEI nova lite 3: earlier than 9.1.0.305(C635E8R2P2) Honor 10 Lite: earlier than 9.1.0.283(C605E8R2P2) Honor 8X: earlier than 9.1.0.221(C461E2R1P1T8) Honor View 20: earlier than 9.1.0.238(C432E1R3P1) Jackman-L22: earlier than 9.1.0.247(C636E2R4P1T8) Paris-L21B: earlier than 9.1.0.331(C432E1R1P2T8) Paris-L21MEB: earlier than 9.1.0.331(C185E4R1P3T8) Paris-L29B: earlier than 9.1.0.331(C636E1R1P3T8) Sydney-AL00: earlier than 9.1.0.212(C00E62R1P7T8) Sydney-L21: earlier than 9.1.0.215(C432E1R1P1T8), earlier than 9.1.0.213(C185E1R1P1T8) Sydney-L21BR: earlier than 9.1.0.213(C185E1R1P2T8) Sydney-L22: earlier than 9.1.0.258(C636E1R1P1T8) Sydney-L22BR: earlier than 9.1.0.258(C636E1R1P1T8) SydneyM-AL00: earlier than 9.1.0.228(C00E78R1P7T8) SydneyM-L01: earlier than 9.1.0.215(C782E2R1P1T8), earlier than 9.1.0.213(C185E1R1P1T8), earlier than 9.1.0.270(C432E3R1P1T8) SydneyM-L03: earlier than 9.1.0.217(C605E1R1P1T8) SydneyM-L21: earlier than 9.1.0.221(C461E1R1P1T8), earlier than 9.1.0.215(C432E4R1P1T8) SydneyM-L22: earlier than 9.1.0.259(C185E1R1P2T8), earlier than 9.1.0.220(C635E1R1P2T8), earlier than 9.1.0.216(C569E1R1P1T8) SydneyM-L23: earlier than 9.1.0.226(C605E2R1P1T8) Yale-L21A: earlier than 9.1.0.154(C432E2R3P2), earlier than 9.1.0.154(C461E2R2P1), earlier than 9.1.0.154(C636E2R2P1) Honor 20: earlier than 9.1.0.152(C00E150R5P1) Honor Magic2: earlier than 10.0.0.187 Honor V20: earlier than 9.1.0.234(C00E234R4P3)

MediumCVSS 5.3 · v3.1—No exploit No fix recorded
Published
Apr 27, 2020
Updated
Jun 16, 2026
EPSS
0.3% · 23th percentile
Follow this CVE

Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.

Report tools

JSON

Action score

21

Monitor

Low priority for now.

CVSS
21 / 40 · 5.3 / 10
CISA KEV
0 / 30 · Not listed
EPSS
0 / 30 · 0.3%

Noroxi analysis

No Noroxi analysis for this record yet

We don't hand-write analysis for the hundreds of thousands of vulnerabilities in the database; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.

We use this product, ask for help

Affected systems

VendorProduct
huaweialp-al00b firmware
huaweialp-al00b
huaweialp-l09 firmware
huaweialp-l09
huaweialp-l29 firmware
huaweialp-l29
huaweibla-l29c firmware
huaweibla-l29c
huaweiberkeley-al20 firmware
huaweiberkeley-al20
huaweiberkeley-l09 firmware
huaweiberkeley-l09

and 82 more

Affected versions

NVD version ranges (for catalog products). Add the product to your stack with a version and matching uses these.

  • huawei alp-al00b firmwarebefore 9.1.0.333\(c00e333r2p1t8\)
  • huawei alp-l09 firmwarebefore 9.1.0.300\(c432e4r1p9t8\)
  • huawei alp-l29 firmwarebefore 9.1.0.315\(c636e5r1p13t8\)
  • huawei berkeley-al20 firmwarebefore 9.1.0.333\(c00e333r2p1t8\)
  • huawei berkeley-l09 firmwarebefore 9.1.0.351\(c432e5r1p13t8\)
  • huawei berkeley-l09 firmwarebefore 9.1.0.350\(c10e3r1p14t8\)
  • huawei berkeley-l09 firmwarebefore 9.1.0.350\(c636e4r1p13t8\)
  • huawei bla-l29c firmwarebefore 9.1.0.321\(c636e4r1p14t8\)
  • huawei bla-l29c firmwarebefore 9.1.0.330\(c432e6r1p12t8\)
  • huawei bla-l29c firmwarebefore 9.1.0.302\(c635e4r1p13t8\)
  • huawei charlotte-l09c firmwarebefore 9.1.0.311\(c185e4r1p11t8\)
  • huawei charlotte-l09c firmwarebefore 9.1.0.345\(c432e8r1p11t8\)
  • huawei charlotte-l29c firmwarebefore 9.1.0.325\(c185e4r1p11t8\)
  • huawei charlotte-l29c firmwarebefore 9.1.0.336\(c605e3r1p12t8\)
  • huawei charlotte-l29c firmwarebefore 9.1.0.335\(c636e3r1p13t8\)
  • huawei charlotte-l29c firmwarebefore 9.1.0.345\(c432e8r1p11t8\)
  • huawei columbia-al10b firmwarebefore 9.1.0.333\(c00e333r1p1t8\)
  • huawei columbia-l29d firmwarebefore 9.1.0.350\(c185e3r1p12t8\)
  • huawei columbia-l29d firmwarebefore 9.1.0.350\(c461e3r1p11t8\)
  • huawei columbia-l29d firmwarebefore 9.1.0.350\(c10e5r1p14t8\)

Versions reported by the vendor

Affected version ranges reported by the assigning authority (huawei). Independent of NVD's CPE analysis and usually ahead of it.

  • Huawei ALP-AL00B

    • Versions earlier than 9.1.0.333(C00E333R2P1T8)affected
  • Huawei ALP-L09

    • Versions earlier than 9.1.0.300(C432E4R1P9T8)affected
  • Huawei ALP-L29

    • Versions earlier than 9.1.0.315(C636E5R1P13T8)affected
  • Huawei Berkeley-AL20

    • Versions earlier than 9.1.0.333(C00E333R2P1T8)affected
  • Huawei Berkeley-L09

    • Versions earlier than 9.1.0.350(C10E3R1P14T8), Versions earlier than 9.1.0.351(C432E5R1P13T8), Versions earlier than 9.1.0.350(C636E4R1P13T8)affected
  • Huawei BLA-L29C

    • Versions earlier than 9.1.0.321(C636E4R1P14T8), Versions earlier than 9.1.0.330(C432E6R1P12T8), Versions earlier than 9.1.0.302(C635E4R1P13T8)affected
  • Huawei Charlotte-L09C

    • Versions earlier than 9.1.0.311(C185E4R1P11T8), Versions earlier than 9.1.0.345(C432E8R1P11T8)affected
  • Huawei Charlotte-L29C

    • Versions earlier than 9.1.0.325(C185E4R1P11T8), Versions earlier than 9.1.0.335(C636E3R1P13T8), Versions earlier than 9.1.0.345(C432E8R1P11T8), Versions earlier than 9.1.0.336(C605E3R1P12T8)affected
  • Huawei Columbia-AL10B

    • Versions earlier than 9.1.0.333(C00E333R1P1T8)affected
  • Huawei Columbia-L29D

    • Versions earlier than 9.1.0.350(C461E3R1P11T8), Versions earlier than 9.1.0.350(C185E3R1P12T8), Versions earlier than 9.1.0.350(C10E5R1P14T8), Versions earlier than 9.1.0.351(C432E5R1P13T8)affected
  • Huawei Cornell-AL00A

    • Versions earlier than 9.1.0.333(C00E333R1P1T8)affected
  • Huawei Cornell-L29A

    • Versions earlier than 9.1.0.328(C185E1R1P9T8), Versions earlier than 9.1.0.328(C432E1R1P9T8), Versions earlier than 9.1.0.330(C461E1R1P9T8), Versions earlier than 9.1.0.328(C636E2R1P12T8)affected

Other highest-scoring records for the same primary product.

  • CVE-2018-7910Some Huawei smartphones ALP-AL00B 8.0.0.118D(C00), ALP-TL00B 8.0.0.118D(C01), BLA-AL00B 8.0.0.118D(C00), BLA-L09C 8.0.0.127(C432), 8.0.0.128
    27Monitor
  • CVE-2019-5303There are two denial of service vulnerabilities on some Huawei smartphones.
    21Monitor
  • CVE-2019-5235Some Huawei smart phones have a null pointer dereference vulnerability.
    21Monitor
  • CVE-2019-19412Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability.
    18Monitor
  • CVE-2018-7911Some Huawei smart phones ALP-AL00B 8.0.0.106(C00), 8.0.0.113(SP2C00), 8.0.0.113(SP3C00), 8.0.0.113(SP7C00), 8.0.0.118(C00), 8.0.0.120(SP2C00
    18Monitor
  • CVE-2018-7901RCS module in Huawei ALP-AL00B smart phones with software versions earlier than 8.0.0.129, BLA-AL00B smart phones with software versions ear
    17Monitor

Remediation

Which version to upgrade to

Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.

No fix version is recorded for this entry. Check the references for vendor advisories.

Exploit status

No known public exploit

No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.

Research context

For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.

Timeline

From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.

No dated events beyond publication.

EPSS, last 120 days

FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).

Patch and commit links

Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.

No commit or PR link among the references.

Finders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.

No credits in the CNA record.

Variant candidates

Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.

No nightly-computed relations.

Chain candidates

An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.

—

Bug bounty scope

No known public program.

Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).

Technical details

Attack conditions

  • Someone on the same network segment can trigger it.
  • No account or password is required.
  • No user action is required.
  • Special conditions such as timing or configuration are required.

If successful

Confidentiality
none
Integrity
none
Availability
high · the service can be disrupted
Attack vector
Adjacent
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
None
Integrity impact
None
Availability impact
High

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

nvd-primary

Change log

No changes recorded on tracked fields yet. Score, KEV, exploit maturity and fix status changes appear here.

References

Vendor advisories and official records. Exploit/PoC links are deliberately left out.

All records