Improper Authentication in HUAWEI Mate 20 Pro Smartphones
CVE-2020-1786

4.6MEDIUM

Key Information:

Vendor
Huawei
Vendor
CVE Published:
9 January 2020

Summary

The HUAWEI Mate 20 Pro smartphones prior to version 10.0.0.175(C00E69R3P8) exhibit an improper authentication vulnerability due to insufficient validation of APK file names in certain scenarios. This flaw enables attackers to impersonate legitimate applications, which could potentially lead to unauthorized access and the ability to bypass essential security functions such as digital balance. This vulnerability poses significant risks to the integrity of user data and the overall security of the device.

Affected Version(s)

HUAWEI Mate 20 Pro Versions earlier than 10.0.0.175(C00E69R3P8)

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.