Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-9109


There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker need to gain certain information in the victim's smartphone to launch the attack, and successful exploit could cause information disclosure.Affected product versions include:HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8),versions earlier than 10.1.0.160(C01E160R2P8);HUAWEI Mate 20 X versions earlier than 10.1.0.160(C00E160R2P8),versions earlier than 10.1.0.160(C01E160R2P8);HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8);Laya-AL00EP versions earlier than 10.1.0.160(C786E160R3P8);Tony-AL00B versions earlier than 10.1.0.160(C00E160R2P11);Tony-TL00B versions earlier than 10.1.0.160(C01E160R2P11).


Published

2020-10-12T14:15:14.340

Last Modified

2024-11-21T05:40:03.407

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.6 (MEDIUM)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.4

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei mate_20_firmware < 10.1.0.160\(c00e160r3p8\) Yes
Hardware huawei mate_20 - No
Operating System huawei mate_20_firmware < 10.1.0.160\(c01e160r2p8\) Yes
Hardware huawei mate_20 - No
Operating System huawei mate_20_x_firmware < 10.1.0.160\(c00e160r2p8\) Yes
Hardware huawei mate_20_x - No
Operating System huawei mate_20_x_firmware < 10.1.0.160\(c01e160r2p8\) Yes
Hardware huawei mate_20_x - No
Operating System huawei p30_pro_firmware < 10.1.0.160\(c00e160r2p8\) Yes
Hardware huawei p30_pro - No
Operating System huawei laya-al00ep_firmware < 10.1.0.160\(c786e160r3p8\) Yes
Hardware huawei laya-al00ep - No
Operating System huawei tony-al00b_firmware < 10.1.0.160\(c00e160r2p11\) Yes
Hardware huawei tony-al00b - No
Operating System huawei tony-tl00b_firmware < 10.1.0.160\(c01e160r2p11\) Yes
Hardware huawei tony-tl00b - No

References