Lucene search

K
cve[email protected]CVE-2020-9074
HistoryJun 05, 2020 - 3:15 p.m.

CVE-2020-9074

2020-06-0515:15:11
CWE-755
web.nvd.nist.gov
55
cve-2020-9074
huawei
smartphones
honor 20 pro
view 20
honor 20
vulnerability
exceptional condition
malformed message

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.7%

Huawei Smartphones HONOR 20 PRO;Honor View 20;HONOR 20 have an improper handling of exceptional condition Vulnerability. A component cannot deal with an exception correctly. Attackers can exploit this vulnerability by sending malformed message. This could compromise normal service of affected phones.

Affected configurations

NVD
Node
huaweihonor_20_proMatch-
AND
huaweihonor_20_pro_firmwareRange<10.0.0.194\(c432e9r5p1\)
Node
huaweihonor_20_proMatch-
AND
huaweihonor_20_pro_firmwareRange<10.0.0.194\(c636e3r3p1\)
Node
huaweihonor_20_proMatch-
AND
huaweihonor_20_pro_firmwareRange<10.0.0.194\(c00e62r8p12\)
Node
huaweihonor_20_proMatch-
AND
huaweihonor_20_pro_firmwareRange<10.0.0.194\(c10e3r3p2\)
Node
huaweihonor_view_20Match-
AND
huaweihonor_view_20_firmwareRange<10.0.0.200\(c185e3r3p3\)
Node
huaweihonor_view_20Match-
AND
huaweihonor_view_20_firmwareRange<10.0.0.201\(c636e3r4p3\)
Node
huaweihonor_view_20Match-
AND
huaweihonor_view_20_firmwareRange<10.0.0.195\(c00e62r4p11\)
Node
huaweihonor_view_20Match-
AND
huaweihonor_view_20_firmwareRange<10.0.0.201\(c10e5r4p3\)
Node
huaweihonor_20_firmwareRange<10.0.0.186\(c185e2r2p1\)
AND
huaweihonor_20Match-
Node
huaweihonor_20_firmwareRange<10.0.0.194\(c432e9r5p1\)
AND
huaweihonor_20Match-

CNA Affected

[
  {
    "product": "HONOR 20 PRO",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.194(C432E9R5P1)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.194(C636E3R3P1)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.194(C00E62R8P12)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.194(C10E3R3P2)"
      }
    ]
  },
  {
    "product": "Honor View 20",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.200(C185E3R3P3)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.201(C636E3R4P3)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.195(C00E62R4P11)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.201(C10E5R4P3)"
      }
    ]
  },
  {
    "product": "HONOR 20",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.186(C185E2R2P1)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.194(C432E9R5P1)"
      }
    ]
  }
]

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.7%

Related for CVE-2020-9074