Information Disclosure Vulnerability in HUAWEI Smartphones
CVE-2020-9109

4.6MEDIUM

Key Information:

Summary

An information disclosure vulnerability exists in multiple HUAWEI smartphones where insufficient identity validation of connected smart wearable devices can be exploited. An attacker must first obtain specific information from the victim's smartphone. Once exploited, this vulnerability can lead to unauthorized access to sensitive information, compromising user privacy and security. Affected models include HUAWEI Mate 20, Mate 20 X, P30 Pro, and other specific variants.

Affected Version(s)

HUAWEI Mate 20;HUAWEI Mate 20 X;HUAWEI P30 Pro;Laya-AL00EP;Tony-AL00B;Tony-TL00B Versions earlier than 10.1.0.160(C00E160R3P8),Versions earlier than 10.1.0.160(C01E160R2P8)

HUAWEI Mate 20;HUAWEI Mate 20 X;HUAWEI P30 Pro;Laya-AL00EP;Tony-AL00B;Tony-TL00B Versions earlier than 10.1.0.160(C00E160R2P8),Versions earlier than 10.1.0.160(C01E160R2P8)

HUAWEI Mate 20;HUAWEI Mate 20 X;HUAWEI P30 Pro;Laya-AL00EP;Tony-AL00B;Tony-TL00B Versions earlier than 10.1.0.160(C00E160R2P8)

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.