CVE-2020-1793Improper Authentication in Huawei Mate 20 Firmware

Severity
4.6MEDIUMNVD
EPSS
0.1%
top 82.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMay 24

Description

There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 0.9 | Impact: 3.6

Affected Packages2 packages

NVDhuawei/mate_20_firmware< 10.0.0.188\(c00e74r3p8\)
NVDhuawei/mate_30_pro_firmware< 10.0.0.203\(c00e202r7p2\)

🔴Vulnerability Details

2
GHSA
GHSA-r7pj-wp43-jmpp: There is an improper authentication vulnerability in several smartphones2022-05-24
CVEList
CVE-2020-1793: There is an improper authentication vulnerability in several smartphones2020-03-20

💬Community

1
Bugzilla
CVE-2020-2162 jenkins: Content-Security-Policy headers for files uploaded leads to XSS2020-03-31
CVE-2020-1793 — Improper Authentication in Huawei | cvebase