Lucene search

K
cveHuaweiCVE-2020-9104
HistoryAug 21, 2020 - 2:15 p.m.

CVE-2020-9104

2020-08-2114:15:11
CWE-401
huawei
web.nvd.nist.gov
27
huawei
p30
smartphones
version
denial of service
vulnerability
cve-2020-9104
nvd

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:N/A:P

CVSS3

4.3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

4.6

Confidence

High

EPSS

0.001

Percentile

25.0%

HUAWEI P30 smartphones with Versions earlier than 10.1.0.123(C431E22R2P5),Versions earlier than 10.1.0.123(C432E22R2P5),Versions earlier than 10.1.0.126(C10E7R5P1),Versions earlier than 10.1.0.126(C185E4R7P1),Versions earlier than 10.1.0.126(C461E7R3P1),Versions earlier than 10.1.0.126(C605E19R1P3),Versions earlier than 10.1.0.126(C636E7R3P4),Versions earlier than 10.1.0.128(C635E3R2P4),Versions earlier than 10.1.0.160(C00E160R2P11),Versions earlier than 10.1.0.160(C01E160R2P11) have a denial of service vulnerability. In specific scenario, due to the improper resource management and memory leak of some feature, the attacker could exploit this vulnerability to cause the device reset.

Affected configurations

Nvd
Vulners
Node
huaweip30_firmwareRange<10.1.0.123\(c431e22r2p5\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.123\(c432e22r2p5\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.126\(c10e7r5p1\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.126\(c185e4r7p1\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.126\(c461e7r3p1\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.126\(c605e19r1p3\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.126\(c636e7r3p4\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.128\(c635e3r2p4\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.160\(c00e160r2p11\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.160\(c01e160r2p11\)
AND
huaweip30Match-
VendorProductVersionCPE
huaweip30_firmware*cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:*
huaweip30-cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "HUAWEI P30",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.123(C431E22R2P5),Versions earlier than 10.1.0.123(C432E22R2P5),Versions earlier than 10.1.0.126(C10E7R5P1),Versions earlier than 10.1.0.126(C185E4R7P1),Versions earlier than 10.1.0.126(C461E7R3P1),Versions earlier than 10.1.0.126(C605E19R1P3),Versions earlier than 10.1.0.126(C636E7R3P4),Versions earlier than 10.1.0.128(C635E3R2P4),Versions earlier than 10.1.0.160(C00E160R2P11),Versions earlier than 10.1.0.160(C01E160R2P11)"
      }
    ]
  }
]

CVSS2

3.3

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:A/AC:L/Au:N/C:N/I:N/A:P

CVSS3

4.3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

4.6

Confidence

High

EPSS

0.001

Percentile

25.0%

Related for CVE-2020-9104