CVE-2020-1801
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does not sufficiently validate the caller's identity in certain share scenario, successful exploit could cause information disclosure. Affected product versions include:Mate 30 Pro versions Versions earlier than 10.0.0.205(C00E202R7P2);Mate 30 versions Versions earlier than 10.0.0.205(C00E201R7P2).
Affected (2)
Products: Huawei: Mate 30 Pro Firmware, Mate 30 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.0.205\(c00e202r7p2\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Mate 30 Pro | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 10.0.0.205\(c00e201r7p2\) |
| Running on/with | Platform Versions |
|---|---|
Huawei Mate 30 | All versions |
References (2)
Source: psirt@huawei.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.