CVE-2019-5227
Description
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do not validate the upgrade package sufficiently, so that the system of smartphone can be downgraded to an older version.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Insufficient upgrade package validation in certain Huawei smartphones and HiSuite allows system downgrade to an older, less secure version.
Vulnerability
CVE-2019-5227 is a version downgrade vulnerability affecting Huawei P30 (versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1)), P30 Pro (versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1)), Mate 20 (versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1)) smartphones, and HiSuite versions earlier than 9.1.0.305 [1]. The device and HiSuite software do not validate the upgrade package sufficiently, allowing an attacker to force the system to accept and install an older version of the firmware [1].
Exploitation
An attacker would need a privileged network position to perform a man-in-the-middle (MITM) attack or otherwise deliver a crafted, malicious downgrade package to the device or HiSuite. The attacker must be able to intercept or spoof the upgrade server response, as the insufficient validation check can be bypassed by providing an unsigned or incorrectly signed older firmware package. No direct user interaction is required if the downgrade is triggered automatically or through a background update mechanism, but the attacker must ensure the device or HiSuite initiates an update check [1].
Impact
Successful exploitation allows an attacker to downgrade the smartphone's system or HiSuite software to an older, unpatched version that may contain known security vulnerabilities. This undermines the integrity of the software supply chain and can re-introduce previously fixed flaws, potentially enabling further compromise of the device [1].
Mitigation
Huawei has released fixed software versions: for P30, ELLE-AL00B 9.1.0.193(C00E190R2P1); for P30 Pro, VOGUE-AL00A 9.1.0.193(C00E190R2P1); for Mate 20, Hima-AL00B 9.1.0.135(C00E133R2P1); and for HiSuite, 9.1.0.305. No workarounds are documented in the available references. Users should upgrade to the latest versions from official Huawei channels to mitigate the risk [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Huawei/P30, P30 Pro, Mate 20 smartphonesdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.huawei.com/en/psirt/security-advisories/huawei-sa-20190904-01-smartphone-enmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.