cbcvebase.
CVE-2020-1872
published 2020-02-18

CVE-2020-1872: Huawei smart phones P10 Plus with versions earlier than 9.1.0.201(C01E75R1P12T8), earlier than 9.1.0.252(C185E2R1P9T8), earlier than 9.1.0.252(C432E4R1P9T8)…

PriorityP418medium4.6CVSS 3.1
AVPACLPRNUINSUCNIHAN
EPSS
0.21%
11.7th percentile
Huawei smart phones P10 Plus with versions earlier than 9.1.0.201(C01E75R1P12T8), earlier than 9.1.0.252(C185E2R1P9T8), earlier than 9.1.0.252(C432E4R1P9T8), and earlier than 9.1.0.255(C576E6R1P8T8) have a digital balance bypass vulnerability. When re-configuring the mobile phone at the digital balance mode, an attacker can perform some operations to bypass the startup wizard, and then open some switch. As a result, the digital balance function is bypassed.

Affected

8 ranges
VendorProductVersion rangeFixed in
huaweihuawei_p10_plus
huaweihuawei_p10_plus
huaweihuawei_p10_plus
huaweihuawei_p10_plus
huaweip10_plus_firmware< 9.1.0.201\(c01e75r1p12t8\)9.1.0.201\(c01e75r1p12t8\)
huaweip10_plus_firmware< 9.1.0.252\(c185e2r1p9t8\)9.1.0.252\(c185e2r1p9t8\)
huaweip10_plus_firmware< 9.1.0.252\(c432e4r1p9t8\)9.1.0.252\(c432e4r1p9t8\)
huaweip10_plus_firmware< 9.1.0.255\(c576e6r1p8t8\)9.1.0.255\(c576e6r1p8t8\)

CVSS provenance

nvdv3.14.6MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.