{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T13:06:09.375","vulnerabilities":[{"cve":{"id":"CVE-2019-5307","sourceIdentifier":"psirt@huawei.com","published":"2019-06-04T19:29:00.727","lastModified":"2026-06-17T02:37:29.413","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Pro versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), are exposed to a message replay vulnerability. For the sake of better compatibility, these devices implement a less strict check on the NAS message sequence number (SN), specifically NAS COUNT. As a result, an attacker can construct a rogue base station and replay the GUTI reallocation command message in certain conditions to tamper with GUTIs, or replay the Identity request message to obtain IMSIs. (Vulnerability ID: HWPSIRT-2019-04107)"},{"lang":"es","value":"Algunos dispositivos Huawei 4G LTE, versiones P30 anteriores a ELE-AL00 9.1.0.162 (C01E160R1P12 / C01E160R2P1) y versiones P30 Pro anteriores a VOG-AL00 9.1.0.162 (C01E160R1P12 / C01E160R2P1), están expuestos a una repetición del mensaje. Por el bien de una mejor compatibilidad, estos dispositivos implementan una verificación menos estricta del número de secuencia de mensaje (SN) de NAS, específicamente el NAS COUNT. Como resultado, un atacante puede construir una estación base maliciosa y reproducir el mensaje de comando de reasignación de GUTI en ciertas condiciones para manipular las GUTI, o reproducir el mensaje de solicitud de identidad para obtener IMSI. (ID de vulnerabilidad: HWPSIRT-2019-04107)"}],"affected":[{"source":"psirt@huawei.com","affectedData":[{"vendor":"Huawei","product":"P30,P30 Pro","versions":[{"version":"The versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1)","status":"affected"},{"version":"The versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1)","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":4.2,"baseSeverity":"MEDIUM","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.5}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:M/Au:N/C:P/I:P/A:N","baseScore":4.3,"accessVector":"ADJACENT_NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":5.5,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-294"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"ele-al00_9.1.0.162","matchCriteriaId":"B148AF2F-F662-4CFA-852F-38EFC80D4D67"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:*","matchCriteriaId":"21EE286C-8111-4F59-8CF1-13C68EA76B21"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"vog-al00_9.1.0.162","matchCriteriaId":"3FCA8B7D-7D85-4A6D-BECE-4BFA896A294D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:huawei:p30_pro:-:*:*:*:*:*:*:*","matchCriteriaId":"6DB671DB-CB5B-46E0-B221-722D051184DE"}]}]}],"references":[{"url":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190529-01-replay-en","source":"psirt@huawei.com","tags":["Vendor Advisory"]},{"url":"https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190529-01-replay-en","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}