Vulnerability Description
HUAWEI Mate 20 versions earlier than 10.0.0.188(C00E74R3P8) have a buffer overflow vulnerability in the Bluetooth module. Due to insufficient input validation, an unauthenticated attacker may craft Bluetooth messages after successful paring, causing buffer overflow. Successful exploit may cause code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Mate 20 Firmware | < 10.0.0.188\(c00e74r3p8\) |
| Huawei | Mate 20 | - |
Related Weaknesses (CWE)
References
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201014-01-bluetoVendor Advisory
- https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201014-01-bluetoVendor Advisory
FAQ
What is CVE-2020-9113?
CVE-2020-9113 is a vulnerability with a CVSS score of 8.0 (HIGH). HUAWEI Mate 20 versions earlier than 10.0.0.188(C00E74R3P8) have a buffer overflow vulnerability in the Bluetooth module. Due to insufficient input validation, an unauthenticated attacker may craft Bl...
How severe is CVE-2020-9113?
CVE-2020-9113 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9113?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Mate 20 Firmware, Huawei Mate 20.