LOW · 2.3

CVE-2020-9252

HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Hono...

Vulnerability Description

HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Honor Magic2 smartphones versions earlier than 10.1.0.160(C00E160R2P11) have a path traversal vulnerability. The system does not sufficiently validate certain pathname from certain process, successful exploit could allow the attacker write files to a crafted path.

CVSS Score

2.3

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
HuaweiMate 20 Firmware< 10.1.0.160\(c00e160r3p8\)
HuaweiMate 20-
HuaweiMate 20 X Firmware< 10.1.0.135\(c00e135r2p8\)
HuaweiMate 20 X-
HuaweiMate 20 Rs Firmware< 10.1.0.160\(c786e160r3p8\)
HuaweiMate 20 Rs-
HuaweiMagic2 Firmware< 10.1.0.160\(c00e160r2p11\)
HuaweiMagic2-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-9252?

CVE-2020-9252 is a vulnerability with a CVSS score of 2.3 (LOW). HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Hono...

How severe is CVE-2020-9252?

CVE-2020-9252 has been rated LOW with a CVSS base score of 2.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-9252?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Mate 20 Firmware, Huawei Mate 20, Huawei Mate 20 X Firmware, Huawei Mate 20 X, Huawei Mate 20 Rs Firmware.