CVE-2020-1804
published 2020-04-27CVE-2020-1804: Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities. Certain driver program does not…
PriorityP425high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
0.60%
44.8th percentile
Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities. Certain driver program does not sufficiently validate certain parameters received, that would lead to several bytes out of bound read. Successful exploit may cause information disclosure or service abnormal. This is 1 out of 3 out of bounds vulnerabilities found. Different than CVE-2020-1805 and CVE-2020-1806.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | honor_v10 | — | — |
| huawei | honor_v10_firmware | < 10.0.0.156\(c00e156r2p4\) | 10.0.0.156\(c00e156r2p4\) |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j43g-xjfm-r8v4: Huawei Honor V10 smartphones with versions earlier than 10
ghsa_unreviewed·2022-05-24·CVSS 7.1
CVE-2020-1806 [HIGH] GHSA-j43g-xjfm-r8v4: Huawei Honor V10 smartphones with versions earlier than 10
Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities. Certain driver program does not sufficiently validate certain parameters received, that would lead to several bytes out of bound read. Successful exploit may cause information disclosure or service abnormal. This is 3 out of 3 out of bounds vulnerabilities found. Different than CVE-2020-1804 and CVE-2020-1805.
GHSA
GHSA-r5pv-cm2h-vfmj: Huawei Honor V10 smartphones with versions earlier than 10
ghsa_unreviewed·2022-05-24·CVSS 7.1
CVE-2020-1804 [HIGH] GHSA-r5pv-cm2h-vfmj: Huawei Honor V10 smartphones with versions earlier than 10
Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities. Certain driver program does not sufficiently validate certain parameters received, that would lead to several bytes out of bound read. Successful exploit may cause information disclosure or service abnormal. This is 1 out of 3 out of bounds vulnerabilities found. Different than CVE-2020-1805 and CVE-2020-1806.
GHSA
GHSA-jh32-659f-ffvm: Huawei Honor V10 smartphones with versions earlier than 10
ghsa_unreviewed·2022-05-24·CVSS 7.1
CVE-2020-1805 [HIGH] GHSA-jh32-659f-ffvm: Huawei Honor V10 smartphones with versions earlier than 10
Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities. Certain driver program does not sufficiently validate certain parameters received, that would lead to several bytes out of bound read. Successful exploit may cause information disclosure or service abnormal. This is 2 out of 3 out of bounds vulnerabilities found. Different than CVE-2020-1804 and CVE-2020-1806.
No detection rules found.
Nuclei
Quixplorer <=2.4.1 - Cross-Site Scripting
nuclei·CVSS 6.1
CVE-2020-24902 [MEDIUM] Quixplorer <=2.4.1 - Cross-Site Scripting
Quixplorer =2.4.2) or apply the vendor-supplied patch to mitigate this vulnerability.
reference:
- https://dl.packetstormsecurity.net/1804-exploits/quixplorer241beta-xss.txt
- https://nvd.nist.gov/vuln/detail/CVE-2020-24902
- https://github.com/ARPSyndicate/kenzer-templates
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cvss-score: 6.1
cve-id: CVE-2020-24902
cwe-id: CWE-79
epss-score: 0.06813
epss-percentile: 0.91322
cpe: cpe:2.3:a:quixplorer_project:quixplorer:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: quixplorer_project
product: quixplorer
shodan-query:
- http.title:"My Download Server"
- http.title:"my download server"
fofa-query: title="my download server"
google-query:
- intitle:"My Download Server"
- intitle:"my download server"
tags:
No writeups or analysis indexed.
2020-04-27
Published