cbcvebase.
CVE-2020-1840
published 2020-01-21

CVE-2020-1840: HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker with high…

PriorityP426medium6CVSS 3.1
AVLACLPRHUINSUCHINAH
EPSS
0.22%
12.7th percentile
HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker with high privilege can execute a specific command to exploit this vulnerability. Successful exploitation may cause information leak and compromise the availability of the smart phones.Affected product versions include: HUAWEI Mate 20 versions Versions earlier than 10.0.0.175(C00E70R3P8)

Affected

3 ranges
VendorProductVersion rangeFixed in
huaweimate_20_firmware<= 10.0.0.175\(c00e70r3p8\)
railsactionview>= 5.0.0 < 5.2.4.35.2.4.3
railsactionview>= 6.0.0 < 6.0.3.16.0.3.1

CVSS provenance

nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
ghsa5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.