CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
30.6%
HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier than 10.1.0.270(C635E3R1P5),Versions earlier than 10.1.0.273(C636E7R2P4);HUAWEI Mate 20 X versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI Mate 20 RS versions Versions earlier than 10.1.0.160(C786E160R3P8);HonorMagic2 versions Versions earlier than 10.0.0.187(C00E61R2P11);Honor20 versions Versions earlier than 10.0.0.175(C00E58R4P11);Honor20 PRO versions Versions earlier than 10.0.0.194(C00E62R8P12);HonorMagic2 versions Versions earlier than 10.0.0.187(C00E61R2P11);HonorV20 versions Versions earlier than 10.0.0.188(C00E62R2P11) have an improper authentication vulnerability. The system does not properly sign certain encrypted file, the attacker should gain the key used to encrypt the file, successful exploit could cause certain file be forged
Vendor | Product | Version | CPE |
---|---|---|---|
huawei | mate_20_firmware | * | cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:* |
huawei | mate_20 | - | cpe:2.3:h:huawei:mate_20:-:*:*:*:*:*:*:* |
huawei | mate_20_pro_firmware | * | cpe:2.3:o:huawei:mate_20_pro_firmware:*:*:*:*:*:*:*:* |
huawei | mate_20_pro | - | cpe:2.3:h:huawei:mate_20_pro:-:*:*:*:*:*:*:* |
huawei | mate_20_x_firmware | * | cpe:2.3:o:huawei:mate_20_x_firmware:*:*:*:*:*:*:*:* |
huawei | mate_20_x | - | cpe:2.3:h:huawei:mate_20_x:-:*:*:*:*:*:*:* |
huawei | p30_firmware | * | cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:* |
huawei | p30 | - | cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:* |
huawei | p30_pro_firmware | * | cpe:2.3:o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:* |
huawei | p30_pro | - | cpe:2.3:h:huawei:p30_pro:-:*:*:*:*:*:*:* |
[
{
"product": "HUAWEI Mate 20;HUAWEI Mate 20 Pro;HUAWEI Mate 20 X;HUAWEI P30;HUAWEI P30 Pro;HUAWEI Mate 20 RS;HonorMagic2;Honor20;Honor20 PRO;HonorMagic2;HonorV20",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "Versions earlier than 10.1.0.160(C00E160R3P8)"
},
{
"status": "affected",
"version": "Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier than 10.1.0.270(C635E3R1P5),Versions earlier than 10.1.0.273(C636E7R2P4)"
},
{
"status": "affected",
"version": "Versions earlier than 10.1.0.160(C00E160R2P8)"
},
{
"status": "affected",
"version": "Versions earlier than 10.1.0.160(C00E160R2P11)"
},
{
"status": "affected",
"version": "Versions earlier than 10.1.0.160(C786E160R3P8)"
},
{
"status": "affected",
"version": "Versions earlier than 10.0.0.187(C00E61R2P11)"
},
{
"status": "affected",
"version": "Versions earlier than 10.0.0.175(C00E58R4P11)"
},
{
"status": "affected",
"version": "Versions earlier than 10.0.0.194(C00E62R8P12)"
},
{
"status": "affected",
"version": "Versions earlier than 10.0.0.188(C00E62R2P11)"
}
]
}
]
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
30.6%