CVE-2020-1794

Severity
4.6MEDIUM
EPSS
0.1%
top 82.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20
Latest updateMay 24

Description

There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 0.9 | Impact: 3.6

Affected Packages2 packages

NVDhuawei/mate_20_firmware< 10.0.0.188\(c00e74r3p8\)
NVDhuawei/mate_30_pro_firmware< 10.0.0.203\(c00e202r7p2\)

🔴Vulnerability Details

2
GHSA
GHSA-4fvr-4264-574g: There is an improper authentication vulnerability in several smartphones2022-05-24
CVEList
CVE-2020-1794: There is an improper authentication vulnerability in several smartphones2020-03-20