4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
5.5 Medium
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
5.2 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
38.6%
There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.
CPE | Name | Operator | Version |
---|---|---|---|
huawei:honor_v10_firmware | huawei honor v10 firmware | lt | 9.1.0.333\(c00e333r2p1t8\) |
[
{
"product": "Honor V10;P30;Mate 20;Honor 9 Lite;Honor 9i;M6;P30 Pro;Honor 20s",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "Versions earlier than 9.1.0.333(C00E333R2P1T8)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.226(C00E220R2P1)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.130(C00E115R2P8T8)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.139(C00E133R3P1)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.130(C00E112R2P10T8)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.143(C636E5R1P5T8)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.120(C00E113R1P6T8)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.1.150(C00E150R1P150)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.0.226(C00E210R2P1)"
},
{
"status": "affected",
"version": "Versions earlier than 9.1.1.132(C00E131R6P1)"
}
]
}
]
4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
5.5 Medium
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
5.2 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
38.6%