Use-After-Free Vulnerability in Huawei Taurus-AN00B Smartphone
CVE-2020-9084

6.5MEDIUM

Key Information:

Vendor
Huawei
Vendor
CVE Published:
18 September 2020

Summary

A use-after-free vulnerability exists in the Huawei Taurus-AN00B smartphone, impacting versions prior to 10.1.0.156 (C00E155R7P2). This weakness allows an authenticated, local attacker to exploit specific operations, potentially leading to privilege escalation and compromising the integrity of the affected service. Users of impacted devices are advised to update to the latest version for enhanced security.

Affected Version(s)

Taurus-AN00B Versions earlier than 10.1.0.156(C00E155R7P2)

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.