Local Authentication Flaw in Huawei Smartphones Exposes Users to Security Risks

CVE-2020-9250

3.3LOW

Key Information

Vendor
Huawei
Status
Huawei Mate 20 Pro
Vendor
CVE Published:
20 December 2024

Summary

CVE-2020-9250 identifies a critical insufficient authentication vulnerability present in several Huawei smartphone models. This vulnerability enables an unauthenticated local attacker to craft and deploy a software package aimed at exploiting these weaknesses. Due to the lack of adequate verification mechanisms, successful exploitation could compromise the affected devices, potentially impacting their functionality and exposing sensitive user data. It is crucial for Huawei users to stay informed about this vulnerability and take proactive steps to mitigate any potential risks.

Affected Version(s)

HUAWEI Mate 20 Pro = Versions earlier than 10.1.0.160(C00E160R3P8)

Refferences

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.