Severity
5.5MEDIUM
EPSS
0.0%
top 92.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 10
Latest updateMay 24

Description

HUAWEI P30 smartphone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper input verification vulnerability. An attribution in a module is not set correctly and some verification is lacked. Attackers with local access can exploit this vulnerability by injecting malicious fragment. This may lead to user information leak.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDhuawei/p30_firmware< 10.1.0.135\(c00e135r2p11\)
CVEListV5huawei_p30Versions earlier than 10.1.0.135(C00E135R2P11)

🔴Vulnerability Details

2
GHSA
GHSA-66f6-j4qh-gpfh: HUAWEI P30 smartphone with versions earlier than 102022-05-24
CVEList
CVE-2020-9258: HUAWEI P30 smartphone with versions earlier than 102020-07-10
CVE-2020-9258 (MEDIUM CVSS 5.5) | HUAWEI P30 smartphone with versions | cvebase.io