CVE-2020-9258
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
HUAWEI P30 smartphone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper input verification vulnerability. An attribution in a module is not set correctly and some verification is lacked. Attackers with local access can exploit this vulnerability by injecting malicious fragment. This may lead to user information leak.
El teléfono inteligente HUAWEI P30 con versiones anteriores a 10.1.0.135(C00E135R2P11), presenta una vulnerabilidad de verificación de entrada inapropiada. Una atribución en un módulo no está configurada correctamente y está careciendo de alguna verificación. Los atacantes con acceso local pueden explotar esta vulnerabilidad mediante la inyección de fragmentos maliciosos. Esto puede conllevar a un filtrado de información del usuario
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-18 CVE Reserved
- 2020-07-10 CVE Published
- 2023-03-26 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200708-02-smartphone-en | 2021-07-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | P30 Firmware Search vendor "Huawei" for product "P30 Firmware" | < 10.1.0.135\(c00e135r2p11\) Search vendor "Huawei" for product "P30 Firmware" and version " < 10.1.0.135\(c00e135r2p11\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | P30 Search vendor "Huawei" for product "P30" | - | - |
Safe
|