CVE-2020-9257

8.8HIGH

Key Information:

Vendor
Huawei
Vendor
CVE Published:
17 July 2020

Summary

HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a buffer overflow vulnerability. The software access data past the end, or before the beginning, of the intended buffer when handling certain operations of certificate, the attacker should trick the user into installing a malicious application, successful exploit may cause code execution.

Affected Version(s)

HUAWEI P30 Pro Versions earlier than 10.1.0.123(C432E19R2P5patch02)

HUAWEI P30 Pro Versions earlier than 10.1.0.126(C10E11R5P1)

HUAWEI P30 Pro Versions earlier than 10.1.0.160(C00E160R2P8)

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.