← Back

CVE-2020-9076

nvd nist
Published: Jun 15, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploitability: 1.6 / Impact: 5.2
Source: NVD

Description

HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier than 10.1.0.135(C00E135R2P8), versions earlier than 10.1.0.135 have an improper authentication vulnerability. Due to the identity of the message sender not being properly verified, an attacker can exploit this vulnerability through man-in-the-middle attack to induce user to access malicious URL.

Affected (4)

3 products
P30 Firmware
P30 Pro Firmware
Tony Al00b Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 10.1.0.135\(c00e135r2p11\)
Running on/withPlatform Versions
Huawei
P30
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.1.0.135\(c00e135r2p8\)
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 10.1.0.135\(c01e135r2p8\)
Running on/withPlatform Versions
Huawei
P30 Pro
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 10.1.0.137\(c00e137r2p11\)
Running on/withPlatform Versions
Huawei
Tony Al00b
All versions

References (2)

Timeline

No history available yet.