Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-9117


HUAWEI nova 4 versions earlier than 10.0.0.165(C01E34R2P4) and SydneyM-AL00 versions earlier than 10.0.0.165(C00E66R1P5) have an out-of-bounds read and write vulnerability. An attacker with specific permissions crafts malformed packet with specific parameter and sends the packet to the affected products. Due to insufficient validation of packet, which may be exploited to cause the information leakage or arbitrary code execution.


Published

2020-12-01T01:15:11.097

Last Modified

2024-11-21T05:40:05.020

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-125
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei nova_4_firmware < 10.0.0.165\(c01e34r2p4\) Yes
Hardware huawei nova_4 - No
Operating System huawei sydneym-al00_firmware < 10.0.0.165\(c00e66r1p5\) Yes
Hardware huawei sydneym-al00 - No

References