CVE-2020-1798
https://notcve.org/view.php?id=CVE-2020-1798
HUAWEI P30 smartphones with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. A logic error occurs when handling NFC work, an attacker should establish a NFC connection to the target phone, and then do a series of operations on the target phone. Successful exploit could allow a guest user do certain operation which is beyond the guest user's privilege. Los teléfonos inteligentes HUAWEI P30 con versiones anteriores a 10.1.0.135(C00E135R2P11), presentan una vulnerabilidad de autenticación inapropiada. Se produce un error lógico cuando se maneja el trabajo de NFC, un atacante debe establecer una conexión NFC con el teléfono objetivo, y luego hacer una serie de operaciones en el mismo. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200527-02-smartphone-en • CWE-287: Improper Authentication •
CVE-2019-5303
https://notcve.org/view.php?id=CVE-2019-5303
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 2 out of 2 vulnerabilities. Different than CVE-2020-5302. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190814-01-mobile-en • CWE-20: Improper Input Validation •
CVE-2019-5302
https://notcve.org/view.php?id=CVE-2019-5302
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1 out of 2 vulnerabilities. Different than CVE-2020-5303. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190814-01-mobile-en • CWE-20: Improper Input Validation •
CVE-2020-1800
https://notcve.org/view.php?id=CVE-2020-1800
HUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access control vulnerability. The software incorrectly restricts access to a function interface from an unauthorized actor, the attacker tricks the user into installing a crafted application, successful exploit could allow the attacker do certain unauthenticated operations. Los teléfonos inteligentes HUAWEI P30 con versiones anteriores a 10.0.0.185(C00E85R1P11), presentan una vulnerabilidad de control de acceso inapropiado. El software restringe incorrectamente el acceso a una interfaz de función de un actor no autorizado, el atacante engaña al usuario para que instale una aplicación diseñada, una explotación con éxito podría permitir al atacante llevar a cabo determinadas operaciones no autenticadas. • https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200325-02-smartphone-en •
CVE-2020-1812
https://notcve.org/view.php?id=CVE-2020-1812
HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentication vulnerability. Due to improperly validation of certain application, an attacker should trick the user into installing a malicious application to exploit this vulnerability. Successful exploit could allow the attacker to bypass the authentication to perform unauthorized operations. Los teléfonos inteligentes HUAWEI P30 con versiones anteriores a 10.0.0.173(C00E73R1P11), presentan una vulnerabilidad de autenticación inapropiada. Debido a una comprobación inapropiada de determinada aplicación, un atacante debe engañar al usuario al instalar una aplicación maliciosa para explotar esta vulnerabilidad. • http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200120-01-smartphone-en • CWE-287: Improper Authentication •