CVE-2020-1792
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Honor V10 smartphones with versions earlier than BKL-AL20 10.0.0.156(C00E156R2P4) and versions earlier than BKL-L09 10.0.0.146(C432E4R1P4) have an out of bounds write vulnerability. The software writes data past the end of the intended buffer because of insufficient validation of certain parameter when initializing certain driver program. An attacker could trick the user into installing a malicious application, successful exploit could cause the device to reboot.
Los teléfonos inteligentes Honor V10 con versiones anteriores a BKL-AL20 10.0.0.156(C00E156R2P4) y versiones anteriores a BKL-L09 10.0.0.146(C432E4R1P4), presentan una vulnerabilidad de escritura fuera de límites. El software escribe datos más allá del final del búfer previsto debido a la insuficiente comprobación de un determinado parámetro cuando se inicializa cierto programa controlador. Un atacante podría engañar al usuario para instalar una aplicación maliciosa, un explotación con éxito podría causar que el dispositivo se reinicie.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-11-29 CVE Reserved
- 2020-02-28 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200226-01-smartphone-en | 2020-03-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Honor V10 Firmware Search vendor "Huawei" for product "Honor V10 Firmware" | < bkl-al20_10.0.0.156\(c00e156r2p4\) Search vendor "Huawei" for product "Honor V10 Firmware" and version " < bkl-al20_10.0.0.156\(c00e156r2p4\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Honor V10 Search vendor "Huawei" for product "Honor V10" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Honor V10 Firmware Search vendor "Huawei" for product "Honor V10 Firmware" | < bkl-l09_10.0.0.146\(c432e4r1p4\) Search vendor "Huawei" for product "Honor V10 Firmware" and version " < bkl-l09_10.0.0.146\(c432e4r1p4\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Honor V10 Search vendor "Huawei" for product "Honor V10" | - | - |
Safe
|