cbcvebase.
CVE-2020-9235
published 2020-09-03

CVE-2020-9235: Huawei smartphones HONOR 20 PRO Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than…

PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.24%
15.3th percentile
Huawei smartphones HONOR 20 PRO Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C185E3R5P1),Versions earlier than 10.1.0.231(C636E3R3P1);Versions earlier than 10.1.0.212(C432E10R3P4),Versions earlier than 10.1.0.213(C636E3R4P3),Versions earlier than 10.1.0.214(C10E5R4P3),Versions earlier than 10.1.0.214(C185E3R3P3);Versions earlier than 10.1.0.212(C00E210R5P1);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C01E160R2P11);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C00E160R8P12);Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C636E3R3P1);Versions earlier than 10.1.0.225(C431E3R1P2),Versions earlier than 10.1.0.225(C432E3R1P2) contain an information vulnerability. A module has a design error that is lack of control of input. Attackers can exploit this vulnerability to obtain some information. This can lead to information leak.

Affected

19 ranges
VendorProductVersion rangeFixed in
huaweihonor_20_pro_firmware< 10.1.0.230\(c432e9r5p1\)10.1.0.230\(c432e9r5p1\)
huaweihonor_20_pro_firmware< 10.1.0.231\(c10e3r3p2\)10.1.0.231\(c10e3r3p2\)
huaweihonor_20_pro_firmware< 10.1.0.231\(c185e3r5p1\)10.1.0.231\(c185e3r5p1\)
huaweihonor_20_pro_firmware< 10.1.0.231\(c636e3r3p1\)10.1.0.231\(c636e3r3p1\)
huaweihonor_view_20_firmware< 10.1.0.212\(c432e10r3p4\)10.1.0.212\(c432e10r3p4\)
huaweihonor_view_20_firmware< 10.1.0.213\(c636e3r4p3\)10.1.0.213\(c636e3r4p3\)
huaweihonor_view_20_firmware< 10.1.0.214\(c10e5r4p3\)10.1.0.214\(c10e5r4p3\)
huaweihonor_view_20_firmware< 10.1.0.214\(c185e3r3p3\)10.1.0.214\(c185e3r3p3\)
huaweioxfords-an00a_firmware< 10.1.0.212\(c00e210r5p1\)10.1.0.212\(c00e210r5p1\)
huaweiprinceton-al10b_firmware< 10.1.0.160\(c00e160r2p11\)10.1.0.160\(c00e160r2p11\)
huaweiprinceton-al10d_firmware< 10.1.0.160\(c00e160r2p11\)10.1.0.160\(c00e160r2p11\)
huaweiprinceton-tl10c_firmware< 10.1.0.160\(c01e160r2p11\)10.1.0.160\(c01e160r2p11\)
huaweitony-al00b_firmware< 10.1.0.160\(c00e160r2p11\)10.1.0.160\(c00e160r2p11\)
huaweiyale-al00a_firmware< 10.1.0.160\(c00e160r8p12\)10.1.0.160\(c00e160r8p12\)
huaweiyale-l21a_firmware< 10.1.0.230\(c432e9r5p1\)10.1.0.230\(c432e9r5p1\)
huaweiyale-l21a_firmware< 10.1.0.231\(c10e3r3p2\)10.1.0.231\(c10e3r3p2\)
huaweiyale-l21a_firmware< 10.1.0.231\(c636e3r3p1\)10.1.0.231\(c636e3r3p1\)
huaweiyale-l61a_firmware< 10.1.0.225\(c431e3r1p2\)10.1.0.225\(c431e3r1p2\)
huaweiyale-l61a_firmware< 10.1.0.225\(c432e3r1p2\)10.1.0.225\(c432e3r1p2\)

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.