cbcvebase.
CVE-2020-9244
published 2020-08-11

CVE-2020-9244: HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier…

PriorityP428medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.23%
14.2th percentile
HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier than 10.1.0.270(C635E3R1P5),Versions earlier than 10.1.0.273(C636E7R2P4);HUAWEI Mate 20 X versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI Mate 20 RS versions Versions earlier than 10.1.0.160(C786E160R3P8);HonorMagic2 versions Versions earlier than 10.0.0.187(C00E61R2P11);Honor20 versions Versions earlier than 10.0.0.175(C00E58R4P11);Honor20 PRO versions Versions earlier than 10.0.0.194(C00E62R8P12);HonorMagic2 versions Versions earlier than 10.0.0.187(C00E61R2P11);HonorV20 versions Versions earlier than 10.0.0.188(C00E62R2P11) have an improper authentication vulnerability. The system does not properly sign certain encrypted file, the attacker should gain the key used to encrypt the file, successful exploit could cause certain file be forged

Affected

12 ranges
VendorProductVersion rangeFixed in
huaweihonor_20_firmware< 10.0.0.175\(c00e58r4p11\)10.0.0.175\(c00e58r4p11\)
huaweihonor_20_pro_firmware< 10.0.0.194\(c00e62r8p12\)10.0.0.194\(c00e62r8p12\)
huaweihonor_magic_2_firmware< 10.0.0.187\(c00e61r2p11\)10.0.0.187\(c00e61r2p11\)
huaweihonor_v20_firmware< 10.0.0.188\(c00e62r2p11\)10.0.0.188\(c00e62r2p11\)
huaweimate_20_firmware< 10.1.0.160\(c00e160r3p8\)10.1.0.160\(c00e160r3p8\)
huaweimate_20_pro_firmware< 10.1.0.270\(c431e7r1p5\)10.1.0.270\(c431e7r1p5\)
huaweimate_20_pro_firmware< 10.1.0.270\(c635e3r1p5\)10.1.0.270\(c635e3r1p5\)
huaweimate_20_pro_firmware< 10.1.0.273\(c636e7r2p4\)10.1.0.273\(c636e7r2p4\)
huaweimate_20_rs_firmware< 10.1.0.160\(c786e160r3p8\)10.1.0.160\(c786e160r3p8\)
huaweimate_20_x_firmware< 10.1.0.160\(c00e160r2p8\)10.1.0.160\(c00e160r2p8\)
huaweip30_firmware< 10.1.0.160\(c00e160r2p11\)10.1.0.160\(c00e160r2p11\)
huaweip30_pro_firmware< 10.1.0.160\(c00e160r2p8\)10.1.0.160\(c00e160r2p8\)

CVSS provenance

nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.