MEDIUM · 5.5

CVE-2020-9065

Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to exploi...

Vulnerability Description

Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to exploit this vulnerability. Successful exploitation may tamper with the information to affect the availability.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
HuaweiTaurus-Al00B Firmware< 10.0.0.203\(c00e201r7p2\)
HuaweiTaurus-Al00B-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-9065?

CVE-2020-9065 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to exploi...

How severe is CVE-2020-9065?

CVE-2020-9065 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-9065?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Taurus-Al00B Firmware, Huawei Taurus-Al00B.