Huawei Mate 20 Firmware vulnerabilities
29 known vulnerabilities affecting huawei/mate_20_firmware.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM18LOW7
Vulnerabilities
Page 1 of 2
CVE-2020-0022P3HIGHCVSS 8.8fixed in 10.0.0.195\(c00e74r3p8\)2020-02-13
CVE-2020-0022 [HIGH] CWE-682 CVE-2020-0022: In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Andr
nvd
CVE-2020-9113P3HIGHCVSS 8.0fixed in 10.0.0.188\(c00e74r3p8\)2020-10-19
CVE-2020-9113 [HIGH] CWE-120 CVE-2020-9113: HUAWEI Mate 20 versions earlier than 10.0.0.188(C00E74R3P8) have a buffer overflow vulnerability in
HUAWEI Mate 20 versions earlier than 10.0.0.188(C00E74R3P8) have a buffer overflow vulnerability in the Bluetooth module. Due to insufficient input validation, an unauthenticated attacker may craft Bluetooth messages after successful paring, causing buffer overflow. Successful exploit may cause code execution.
nvd
CVE-2020-9247P3HIGHCVSS 7.8fixed in 10.1.0.160\(c00e160r3p8\)2020-12-07
CVE-2020-9247 [HIGH] CWE-120 CVE-2020-9247: There is a buffer overflow vulnerability in several Huawei products. The system does not sufficientl
There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code executio
nvd
CVE-2019-5225P3HIGHCVSS 7.8fixed in hima-al00b_9.1.0.135\(c00e200r2p1\)2019-11-29
CVE-2019-5225 [HIGH] CWE-120 CVE-2019-5225: P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E19
P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12) have a buffer overflow vulnerability on several , the system does not properly validate certain length parameter which an applicati
nvd
CVE-2020-9244P4MEDIUMCVSS 6.8fixed in 10.1.0.160\(c00e160r3p8\)2020-08-11
CVE-2020-9244 [MEDIUM] CVE-2020-9244: HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Ve
HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier than 10.1.0.270(C635E3R1P5),Versions earlier than 10.1.0.273(C636E7R2P4);HUAWEI Mate 20 X versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI P30 versions Versions earlier than 10.1.0.160(C00
nvd
CVE-2020-9081P4MEDIUMCVSS 6.8fixed in 10.1.0.160\(c00e160r3p8\)fixed in 10.1.0.160\(c01e160r2p8\)2024-12-27
CVE-2020-9081 [MEDIUM] CWE-285 CVE-2020-9081: There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perfo
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144)
This vulnerability has been assigned a Common Vulnerabilities and Exposures
nvd
CVE-2020-1787P4MEDIUMCVSS 6.6fixed in 9.1.0.139\(c00e133r3p1\)2020-01-09
CVE-2020-1787 [MEDIUM] CWE-287 CVE-2020-1787: HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authenticat
HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. The system has a logic error under certain scenario, successful exploit could allow the attacker who gains the privilege of guest user to access to the host user's desktop in an instant, without unlocking the screen lock of the host u
nvd
CVE-2020-1796P4MEDIUMCVSS 6.6≤ 10.0.0.188\(c00e74r3p8\)2020-03-20
CVE-2020-1796 [MEDIUM] CWE-863 CVE-2020-1796: There is an improper authorization vulnerability in several smartphones. The software incorrectly pe
There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successful exploit could allow a low privilege user to do certain operation which the user are supposed not to do.Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R
nvd
CVE-2020-1840P4MEDIUMCVSS 6.0≤ 10.0.0.175\(c00e70r3p8\)2020-01-21
CVE-2020-1840 [MEDIUM] CWE-287 CVE-2020-1840: HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient a
HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability. A local attacker with high privilege can execute a specific command to exploit this vulnerability. Successful exploitation may cause information leak and compromise the availability of the smart phones.Affected product versi
nvd
CVE-2020-1794P4MEDIUMCVSS 4.6fixed in 10.0.0.188\(c00e74r3p8\)2020-03-20
CVE-2020-1794 [MEDIUM] CWE-287 CVE-2020-1794: There is an improper authentication vulnerability in several smartphones. The applock does not perfo
There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3
nvd
CVE-2020-1793P4MEDIUMCVSS 4.6fixed in 10.0.0.188\(c00e74r3p8\)2020-03-20
CVE-2020-1793 [MEDIUM] CWE-287 CVE-2020-1793: There is an improper authentication vulnerability in several smartphones. The applock does not perfo
There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3
nvd
CVE-2019-5251P4MEDIUMCVSS 5.5fixed in 9.1.0.139\(c00e133r3p1\)2019-12-13
CVE-2019-5251 [MEDIUM] CWE-22 CVE-2019-5251: There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficien
There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.
nvd
CVE-2019-5226P4MEDIUMCVSS 5.5fixed in hima-al00b_9.1.0.135\(c00e133r2p1\)2019-11-29
CVE-2019-5226 [MEDIUM] CWE-346 CVE-2019-5226: P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E19
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do
nvd
CVE-2019-5227P4MEDIUMCVSS 5.5fixed in hima-al00b_9.1.0.135\(c00e133r2p1\)2019-11-29
CVE-2019-5227 [MEDIUM] CWE-346 CVE-2019-5227: P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E19
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do
nvd
CVE-2019-5302P4MEDIUMCVSS 5.3fixed in 9.1.0.131\(c00e131r3p1\)2020-04-27
CVE-2019-5302 [MEDIUM] CWE-20 CVE-2019-5302: There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send spe
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1 out of 2 vulnerabilities. Different
nvd
CVE-2019-5303P4MEDIUMCVSS 5.3fixed in 9.1.0.131\(c00e131r3p1\)2020-04-27
CVE-2019-5303 [MEDIUM] CWE-20 CVE-2019-5303: There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send spe
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 2 out of 2 vulnerabilities. Different
nvd
CVE-2019-5220P4MEDIUMCVSS 4.6fixed in hima-al00b\/hima-tl00b_9.0.0.200\(c00e200r2p1\)2019-07-10
CVE-2019-5220 [MEDIUM] CWE-863 CVE-2019-5220: There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system do
There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently verify the permission, an attacker could do a certain operation on certain step of setup wizard. Successful exploit could allow the attacker bypass the FRP protection. Affected products: Mate 20 X, versions earlier than Ever-AL00B 9.
nvd
CVE-2021-22440P4MEDIUMCVSS 4.6v9.0.0.195\(c01e195r2p1\)v9.1.0.139\(c00e133r3p1\)2021-07-13
CVE-2021-22440 [MEDIUM] CWE-22 CVE-2021-22440: There is a path traversal vulnerability in some Huawei products. The vulnerability is due to that th
There is a path traversal vulnerability in some Huawei products. The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly validate the pathname. Successful exploit could allow t
nvd
CVE-2020-9092P4MEDIUMCVSS 4.6fixed in 10.1.0.163\(c00e160r3p8\)2020-10-19
CVE-2020-9092 [MEDIUM] CWE-79 CVE-2020-9092: HUAWEI Mate 20 versions earlier than 10.1.0.163(C00E160R3P8) have a JavaScript injection vulnerabili
HUAWEI Mate 20 versions earlier than 10.1.0.163(C00E160R3P8) have a JavaScript injection vulnerability. A module does not verify a specific input. This could allow attackers to bypass filter mechanism to launch JavaScript injection. This could compromise normal service of the affected module.
nvd
CVE-2020-9109P4MEDIUMCVSS 4.6fixed in 10.1.0.160\(c00e160r3p8\)fixed in 10.1.0.160\(c01e160r2p8\)2020-10-12
CVE-2020-9109 [MEDIUM] CWE-287 CVE-2020-9109: There is an information disclosure vulnerability in several smartphones. The device does not suffici
There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker need to gain certain information in the victim's smartphone to launch the attack, and successful exploit could cause information disclosure.Affected product
nvd
1 / 2Next →