Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-9254


HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a logic check error vulnerability. A logic error occurs when the software checking the size of certain parameter, the attacker should trick the user into installing a malicious application, successful exploit may cause code execution.


Published

2020-07-17T23:15:11.617

Last Modified

2024-11-21T05:40:16.763

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei p30_pro_firmware < 10.1.0.123\(c432e19r2p5patch02\) Yes
Hardware huawei p30_pro - No
Operating System huawei p30_pro_firmware < 10.1.0.126\(c10e11r5p1\) Yes
Hardware huawei p30_pro - No
Operating System huawei p30_pro_firmware < 10.1.0.160\(c00e160r2p8\) Yes
Hardware huawei p30_pro - No

References