Improper Authentication in HUAWEI P30 and P30 Pro Smartphones
CVE-2020-9076

6.8MEDIUM

Key Information:

Vendor
Huawei
Vendor
CVE Published:
15 June 2020

Summary

The HUAWEI P30, P30 Pro, and Tony-AL00B smartphones possess an improper authentication vulnerability that can be exploited by attackers through man-in-the-middle techniques. This flaw arises from the failure to adequately verify the identity of message senders, potentially leading users to malicious URLs and compromising their security. It is crucial for users to update their devices to the latest software versions to mitigate associated risks.

Affected Version(s)

HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B Versions earlier than 10.1.0.135(C00E135R2P11)

HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B Versions earlier than 10.1.0.135(C00E135R2P8),Versions earlier than 10.1.0.135(C01E135R2P8)

HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B Versions earlier than 10.1.0.137(C00E137R2P11)

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.