Lucene search

K
cve[email protected]CVE-2020-9203
HistoryJan 13, 2021 - 10:15 p.m.

CVE-2020-9203

2021-01-1322:15:14
CWE-400
web.nvd.nist.gov
19
huawei
p30
cve-2020-9203
vulnerability
resource management
local attackers
broadcast message
user experience

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

4.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

There is a resource management errors vulnerability in Huawei P30. Local attackers construct broadcast message for some application, causing this application to send this broadcast message and impact the customer’s use experience.

Affected configurations

NVD
Node
huaweip30_firmwareRange<10.1.0.168\(c00e168r2p11\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.168\(c01e168r2p11\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.176\(c635e4r2p4\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.177\(c636e8r3p4\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.179\(c10e8r5p1\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.179\(c185e7r7p1\)
AND
huaweip30Match-
Node
huaweip30_firmwareRange<10.1.0.179\(c605e23r1p3\)
AND
huaweip30Match-

CNA Affected

[
  {
    "product": "HUAWEI P30",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.168(C00E168R2P11),Versions earlier than 10.1.0.168(C01E168R2P11),Versions earlier than 10.1.0.176(C635E4R2P4),Versions earlier than 10.1.0.177(C636E8R3P4),Versions earlier than 10.1.0.179(C10E8R5P1),Versions earlier than 10.1.0.179(C185E7R7P1),Versions earlier than 10.1.0.179(C605E23R1P3"
      }
    ]
  }
]

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

4.2 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2020-9203