Vulnerability Description
There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful exploitation may impact the service. (Vulnerability ID: HWPSIRT-2019-12302) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9250.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Mate 20 Pro Firmware | 10.1.0.160\(c00e160r3p8\) |
| Huawei | Mate 20 Pro | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200729-01-smartphBroken LinkVendor Advisory
FAQ
What is CVE-2020-9250?
CVE-2020-9250 is a vulnerability with a CVSS score of 3.3 (LOW). There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient veri...
How severe is CVE-2020-9250?
CVE-2020-9250 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9250?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Mate 20 Pro Firmware, Huawei Mate 20 Pro.