CVE-2020-9252
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Honor Magic2 smartphones versions earlier than 10.1.0.160(C00E160R2P11) have a path traversal vulnerability. The system does not sufficiently validate certain pathname from certain process, successful exploit could allow the attacker write files to a crafted path.
Los teléfonos inteligentes HUAWEI Mate 20 versiones anteriores a 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versiones anteriores a 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versiones anteriores a 10.1.0.160(C786E160R3P8) y Honor Magic2 versiones anteriores a 10.1. 0.160(C00E160R2P11), presenta una vulnerabilidad de salto de ruta. El sistema no comprueba suficientemente determinado nombre de ruta de un determinado proceso, una explotación con éxito podría permitir a un atacante escribir archivos en una ruta diseñada
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-18 CVE Reserved
- 2020-07-17 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200715-07-smartphone-en | 2020-07-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Mate 20 Firmware Search vendor "Huawei" for product "Mate 20 Firmware" | < 10.1.0.160\(c00e160r3p8\) Search vendor "Huawei" for product "Mate 20 Firmware" and version " < 10.1.0.160\(c00e160r3p8\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Mate 20 Search vendor "Huawei" for product "Mate 20" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Mate 20 X Firmware Search vendor "Huawei" for product "Mate 20 X Firmware" | < 10.1.0.135\(c00e135r2p8\) Search vendor "Huawei" for product "Mate 20 X Firmware" and version " < 10.1.0.135\(c00e135r2p8\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Mate 20 X Search vendor "Huawei" for product "Mate 20 X" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Mate 20 Rs Firmware Search vendor "Huawei" for product "Mate 20 Rs Firmware" | < 10.1.0.160\(c786e160r3p8\) Search vendor "Huawei" for product "Mate 20 Rs Firmware" and version " < 10.1.0.160\(c786e160r3p8\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Mate 20 Rs Search vendor "Huawei" for product "Mate 20 Rs" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Magic2 Firmware Search vendor "Huawei" for product "Magic2 Firmware" | < 10.1.0.160\(c00e160r2p11\) Search vendor "Huawei" for product "Magic2 Firmware" and version " < 10.1.0.160\(c00e160r2p11\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Magic2 Search vendor "Huawei" for product "Magic2" | - | - |
Safe
|