← Back

CVE-2020-9117

nvd nist
Published: Dec 1, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

HUAWEI nova 4 versions earlier than 10.0.0.165(C01E34R2P4) and SydneyM-AL00 versions earlier than 10.0.0.165(C00E66R1P5) have an out-of-bounds read and write vulnerability. An attacker with specific permissions crafts malformed packet with specific parameter and sends the packet to the affected products. Due to insufficient validation of packet, which may be exploited to cause the information leakage or arbitrary code execution.

Affected (2)

2 products
Nova 4 Firmware
Sydneym Al00 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 10.0.0.165\(c01e34r2p4\)
Running on/withPlatform Versions
Huawei
Nova 4
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 10.0.0.165\(c00e66r1p5\)
Running on/withPlatform Versions
Huawei
Sydneym Al00
All versions

Timeline

No history available yet.