Path Traversal Vulnerability in HUAWEI Mate 20 and Honor Magic2 Smartphones
CVE-2020-9252

2.3LOW

Key Information:

Vendor
Huawei
Vendor
CVE Published:
17 July 2020

Summary

Multiple HUAWEI smartphone models, including the Mate 20, Mate 20 X, and Honor Magic2, have a path traversal vulnerability. This issue arises from inadequate validation of certain pathname inputs from specific processes, which could be exploited by attackers. A successful attack may enable unauthorized file writing to specified paths within the system, potentially compromising user data and device integrity.

Affected Version(s)

Honor Magic2 Versions earlier than 10.1.0.160(C00E160R2P11)

HUAWEI Mate 20 Versions earlier than 10.1.0.160(C00E160R3P8)

HUAWEI Mate 20 RS Versions earlier than 10.1.0.160(C786E160R3P8)

References

CVSS V3.1

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.