Lucene search

K
cveHuaweiCVE-2020-9244
HistoryAug 11, 2020 - 7:15 p.m.

CVE-2020-9244

2020-08-1119:15:17
huawei
web.nvd.nist.gov
36
huawei
honor
mate 20
mate 20 pro
p30
p30 pro
mate 20 x
mate 20 rs
honor magic2
honor20
honor20 pro
honorv20
cve-2020-9244
nvd

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

30.6%

HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier than 10.1.0.270(C635E3R1P5),Versions earlier than 10.1.0.273(C636E7R2P4);HUAWEI Mate 20 X versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI Mate 20 RS versions Versions earlier than 10.1.0.160(C786E160R3P8);HonorMagic2 versions Versions earlier than 10.0.0.187(C00E61R2P11);Honor20 versions Versions earlier than 10.0.0.175(C00E58R4P11);Honor20 PRO versions Versions earlier than 10.0.0.194(C00E62R8P12);HonorMagic2 versions Versions earlier than 10.0.0.187(C00E61R2P11);HonorV20 versions Versions earlier than 10.0.0.188(C00E62R2P11) have an improper authentication vulnerability. The system does not properly sign certain encrypted file, the attacker should gain the key used to encrypt the file, successful exploit could cause certain file be forged

Affected configurations

Nvd
Vulners
Node
huaweimate_20_firmwareRange<10.1.0.160\(c00e160r3p8\)
AND
huaweimate_20Match-
Node
huaweimate_20_pro_firmwareRange<10.1.0.270\(c431e7r1p5\)
AND
huaweimate_20_proMatch-
Node
huaweimate_20_x_firmwareRange<10.1.0.160\(c00e160r2p8\)
AND
huaweimate_20_xMatch-
Node
huaweip30_firmwareRange<10.1.0.160\(c00e160r2p11\)
AND
huaweip30Match-
Node
huaweip30_pro_firmwareRange<10.1.0.160\(c00e160r2p8\)
AND
huaweip30_proMatch-
Node
huaweimate_20_rs_firmwareRange<10.1.0.160\(c786e160r3p8\)
AND
huaweimate_20_rsMatch-
Node
huaweihonor_magic_2_firmwareRange<10.0.0.187\(c00e61r2p11\)
AND
huaweihonor_magic_2Match-
Node
huaweihonor_20_firmwareRange<10.0.0.175\(c00e58r4p11\)
AND
huaweihonor_20Match-
Node
huaweihonor_20_pro_firmwareRange<10.0.0.194\(c00e62r8p12\)
AND
huaweihonor_20_proMatch-
Node
huaweihonor_v20Match-
AND
huaweihonor_v20_firmwareRange<10.0.0.188\(c00e62r2p11\)
Node
huaweimate_20_proMatch-
AND
huaweimate_20_pro_firmwareRange<10.1.0.270\(c635e3r1p5\)
Node
huaweimate_20_proMatch-
AND
huaweimate_20_pro_firmwareRange<10.1.0.273\(c636e7r2p4\)
Node
huaweihonor_magic_2Match-
AND
huaweihonor_magic_2_firmwareRange<10.0.0.187\(c00e61r2p11\)
VendorProductVersionCPE
huaweimate_20_firmware*cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:*
huaweimate_20-cpe:2.3:h:huawei:mate_20:-:*:*:*:*:*:*:*
huaweimate_20_pro_firmware*cpe:2.3:o:huawei:mate_20_pro_firmware:*:*:*:*:*:*:*:*
huaweimate_20_pro-cpe:2.3:h:huawei:mate_20_pro:-:*:*:*:*:*:*:*
huaweimate_20_x_firmware*cpe:2.3:o:huawei:mate_20_x_firmware:*:*:*:*:*:*:*:*
huaweimate_20_x-cpe:2.3:h:huawei:mate_20_x:-:*:*:*:*:*:*:*
huaweip30_firmware*cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:*
huaweip30-cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:*
huaweip30_pro_firmware*cpe:2.3:o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:*
huaweip30_pro-cpe:2.3:h:huawei:p30_pro:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CNA Affected

[
  {
    "product": "HUAWEI Mate 20;HUAWEI Mate 20 Pro;HUAWEI Mate 20 X;HUAWEI P30;HUAWEI P30 Pro;HUAWEI Mate 20 RS;HonorMagic2;Honor20;Honor20 PRO;HonorMagic2;HonorV20",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.160(C00E160R3P8)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier than 10.1.0.270(C635E3R1P5),Versions earlier than 10.1.0.273(C636E7R2P4)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.160(C00E160R2P8)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.160(C00E160R2P11)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.1.0.160(C786E160R3P8)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.187(C00E61R2P11)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.175(C00E58R4P11)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.194(C00E62R8P12)"
      },
      {
        "status": "affected",
        "version": "Versions earlier than 10.0.0.188(C00E62R2P11)"
      }
    ]
  }
]

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

6.8

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

30.6%

Related for CVE-2020-9244