cbcvebase.
CVE-2020-9081
published 2024-12-27

CVE-2020-9081: There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this…

PriorityP428medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.20%
9.4th percentile
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081.

Affected

18 ranges
VendorProductVersion rangeFixed in
huaweihuawei_mate_20
huaweihuawei_mate_20
huaweihuawei_p30
huaweihuawei_p30_pro
huaweihuawei_p30_pro
huaweimate_20_firmware< 10.1.0.160\(c00e160r3p8\)10.1.0.160\(c00e160r3p8\)
huaweimate_20_firmware< 10.1.0.160\(c01e160r2p8\)10.1.0.160\(c01e160r2p8\)
huaweip30_firmware< 10.1.0.160\(c00e160r2p11\)10.1.0.160\(c00e160r2p11\)
huaweip30_pro_firmware< 10.1.0.160\(c00e160r2p8\)10.1.0.160\(c00e160r2p8\)
huaweip30_pro_firmware< 10.1.0.160\(c01e160r2p8\)10.1.0.160\(c01e160r2p8\)
huaweiprinceton-al10d
huaweiprinceton-al10d_firmware< 10.1.0.160\(c00e160r2p11\)10.1.0.160\(c00e160r2p11\)
huaweiyale-al00a
huaweiyale-al00a_firmware< 10.1.0.160\(c00e160r8p12\)10.1.0.160\(c00e160r8p12\)
huaweiyale-al50a
huaweiyale-al50a_firmware< 10.1.0.88\(c00e88r8p1\)10.1.0.88\(c00e88r8p1\)
huaweiyalep-al10b
huaweiyalep-al10b_firmware< 10.1.0.160\(c00e160r8p12\)10.1.0.160\(c00e160r8p12\)
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.