HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Honor Magic2 smartphones versions earlier than 10.1.0.160(C00E160R2P11) have a path traversal vulnerability. The system does not sufficiently validate certain pathname from certain process, successful exploit could allow the attacker write files to a crafted path.
2020-07-17T23:15:11.537
2024-11-21T05:40:16.590
Modified
CVSSv3.1: 2.3 (LOW)
AV:L/AC:L/Au:N/C:N/I:P/A:N
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | huawei | mate_20_firmware | < 10.1.0.160\(c00e160r3p8\) | Yes |
| Hardware | huawei | mate_20 | - | No |
| Operating System | huawei | mate_20_x_firmware | < 10.1.0.135\(c00e135r2p8\) | Yes |
| Hardware | huawei | mate_20_x | - | No |
| Operating System | huawei | mate_20_rs_firmware | < 10.1.0.160\(c786e160r3p8\) | Yes |
| Hardware | huawei | mate_20_rs | - | No |
| Operating System | huawei | magic2_firmware | < 10.1.0.160\(c00e160r2p11\) | Yes |
| Hardware | huawei | magic2 | - | No |