Severity
3.3LOW
EPSS
0.1%
top 70.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 27
Latest updateMay 24

Description

HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information exposure vulnerability. The system does not properly authenticate the application that access a specified interface. Attackers can trick users into installing malicious software to exploit this vulnerability and obtain some information about the device. Successful exploit may cause information disclosure.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

NVDhuawei/p30_firmware< 10.1.0.160\(c00e160r2p11\)
CVEListV5huawei_p30Versions earlier than 10.1.0.160(C00E160R2P11)

🔴Vulnerability Details

2
GHSA
GHSA-35hp-m7hg-c3cm: HUAWEI P30 smart phones with versions earlier than 102022-05-24
CVEList
CVE-2020-9077: HUAWEI P30 smart phones with versions earlier than 102020-07-27
CVE-2020-9077 (LOW CVSS 3.3) | HUAWEI P30 smart phones with versio | cvebase.io