VYPR
Unrated severityNVD Advisory· Published Nov 29, 2019· Updated Aug 4, 2024

CVE-2019-5227

CVE-2019-5227

Description

P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Insufficient upgrade package validation in certain Huawei smartphones and HiSuite allows system downgrade to an older, less secure version.

Vulnerability

CVE-2019-5227 is a version downgrade vulnerability affecting Huawei P30 (versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1)), P30 Pro (versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1)), Mate 20 (versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1)) smartphones, and HiSuite versions earlier than 9.1.0.305 [1]. The device and HiSuite software do not validate the upgrade package sufficiently, allowing an attacker to force the system to accept and install an older version of the firmware [1].

Exploitation

An attacker would need a privileged network position to perform a man-in-the-middle (MITM) attack or otherwise deliver a crafted, malicious downgrade package to the device or HiSuite. The attacker must be able to intercept or spoof the upgrade server response, as the insufficient validation check can be bypassed by providing an unsigned or incorrectly signed older firmware package. No direct user interaction is required if the downgrade is triggered automatically or through a background update mechanism, but the attacker must ensure the device or HiSuite initiates an update check [1].

Impact

Successful exploitation allows an attacker to downgrade the smartphone's system or HiSuite software to an older, unpatched version that may contain known security vulnerabilities. This undermines the integrity of the software supply chain and can re-introduce previously fixed flaws, potentially enabling further compromise of the device [1].

Mitigation

Huawei has released fixed software versions: for P30, ELLE-AL00B 9.1.0.193(C00E190R2P1); for P30 Pro, VOGUE-AL00A 9.1.0.193(C00E190R2P1); for Mate 20, Hima-AL00B 9.1.0.135(C00E133R2P1); and for HiSuite, 9.1.0.305. No workarounds are documented in the available references. Users should upgrade to the latest versions from official Huawei channels to mitigate the risk [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • Huawei/P30, P30 Pro, Mate 20 smartphonesdescription
  • Huawei/Mate 20llm-create
    Range: <Hima-AL00B 9.1.0.135(C00E133R2P1)
  • Huawei/P30llm-fuzzy
    Range: <ELLE-AL00B 9.1.0.193(C00E190R2P1)
  • Huawei/P30 Prollm-fuzzy
    Range: <VOGUE-AL00A 9.1.0.193(C00E190R2P1)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.