CVE-2020-9263

CWE-416Use After Free3 documents3 sources
Severity
7.8HIGH
EPSS
0.3%
top 45.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 19
Latest updateMay 24

Description

HUAWEI Mate 30 versions earlier than 10.1.0.150(C00E136R5P3) and HUAWEI P30 version earlier than 10.1.0.160(C00E160R2P11) have a use after free vulnerability. There is a condition exists that the system would reference memory after it has been freed, the attacker should trick the user into running a crafted application with common privilege, successful exploit could cause code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDhuawei/mate_30_firmware< 10.1.0.150\(c00e136r5p3\)
NVDhuawei/p30_firmware< 10.1.0.160\(c00e160r2p11\)

🔴Vulnerability Details

2
GHSA
GHSA-xh3q-7hfg-v6rr: HUAWEI Mate 30 versions earlier than 102022-05-24
CVEList
CVE-2020-9263: HUAWEI Mate 30 versions earlier than 102020-10-19
CVE-2020-9263 (HIGH CVSS 7.8) | HUAWEI Mate 30 versions earlier tha | cvebase.io