Out-Of-Bounds Read and Write Vulnerability in HUAWEI nova 4 and SydneyM-AL00 Products
CVE-2020-9117

7.8HIGH

Key Information:

Vendor
Huawei
Vendor
CVE Published:
1 December 2020

Summary

Certain versions of the HUAWEI nova 4 and SydneyM-AL00 are vulnerable to an out-of-bounds read and write issue. This vulnerability allows an attacker with specific permissions to craft a malformed packet containing specific parameters. When this packet is sent to the affected devices, it leads to insufficient validation, which can result in information leakage and the potential for arbitrary code execution. It's important for users of these devices to be aware of this vulnerability and take necessary precautions.

Affected Version(s)

HUAWEI nova 4;SydneyM-AL00 Versions earlier than 10.0.0.165(C01E34R2P4)

HUAWEI nova 4;SydneyM-AL00 Versions earlier than 10.0.0.165(C00E66R1P5)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.