Severity
3.3LOW
EPSS
0.0%
top 85.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 20

Description

There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful exploitation may impact the service. (Vulnerability ID: HWPSIRT-2019-12302) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9250.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5huawei/huawei_mate_20_proVersions earlier than 10.1.0.160(C00E160R3P8)
NVDhuawei/mate_20_pro_firmware10.1.0.160\(c00e160r3p8\)

🔴Vulnerability Details

2
GHSA
GHSA-j9vj-qv55-qq58: There is an insufficient authentication vulnerability in some Huawei smart phone2024-12-20
CVEList
CVE-2020-9250: There is an insufficient authentication vulnerability in some Huawei smart phone2024-12-20
CVE-2020-9250 (LOW CVSS 3.3) | There is an insufficient authentica | cvebase.io