cbcvebase.

Huawei P30 Firmware vulnerabilities

42 known vulnerabilities affecting huawei/p30_firmware.

Total CVEs
42
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH12MEDIUM27LOW3

Vulnerabilities

Page 1 of 3
CVE-2020-0022P3HIGHCVSS 8.8fixed in 10.0.0.190\(c432e22r2p5\)2020-02-13
CVE-2020-0022 [HIGH] CWE-682 CVE-2020-0022: In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Andr
nvd
CVE-2019-5265P3HIGHCVSS 7.5v9.1.0.193\(c00e190r2p1\)2019-12-23
CVE-2019-5265 [HIGH] CVE-2019-5265: Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an improper access control vulner Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an improper access control vulnerability. The function incorrectly controls certain access messages, attackers can simulate a sender to steal P2P network information. Successful exploit may cause information leakage.
nvd
CVE-2020-1812P3HIGHCVSS 7.8fixed in 10.0.0.173\(c00e73r1p11\)2020-02-18
CVE-2020-1812 [HIGH] CWE-287 CVE-2020-1812: HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentic HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentication vulnerability. Due to improperly validation of certain application, an attacker should trick the user into installing a malicious application to exploit this vulnerability. Successful exploit could allow the attacker to bypass the authentication to
nvd
CVE-2019-5266P3HIGHCVSS 7.5v9.1.0.193\(c00e190r2p1\)2019-12-23
CVE-2019-5266 [HIGH] CWE-20 CVE-2019-5266: Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation vulnerability. Attackers can exploit this vulnerability by sending crafted packets to the affected device. Successful exploit may cause the function will be disabled.
nvd
CVE-2021-22331P3HIGHCVSS 7.5fixed in 10.1.0.165\(c01e165r2p11\)fixed in 11.0.0.118\(c635e2r1p3\)+7 more2021-04-28
CVE-2021-22331 [HIGH] CWE-74 CVE-2021-22331: There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verif There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs sufficiently. Attackers can exploit this vulnerability by sending a malicious application request to launch JavaScript injection. This may compromise normal service. Affected product versions include HUAWEI P30 versions earlier than 10.1.0.
nvd
CVE-2019-5288P3HIGHCVSS 7.8fixed in elle-al00b_9.1.0.193\(c00e190r2p1\)vVersions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1)2019-11-13
CVE-2019-5288 [HIGH] CWE-190 CVE-2019-5288: P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overfl P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due to insufficient check on specific parameters. An attacker tricks the user into installing a malicious application, obtains the root permission and constructs specific parameters to the camera program to exploit this vulnerability. Suc
nvd
CVE-2019-5287P3HIGHCVSS 7.8fixed in elle-al00b_9.1.0.193\(c00e190r2p1\)vVersions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1)2019-11-13
CVE-2019-5287 [HIGH] CWE-190 CVE-2019-5287: P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overfl P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due to insufficient check on specific parameters. An attacker tricks the user into installing a malicious application, obtains the root permission and constructs specific parameters to the camera program to exploit this vulnerability. Suc
nvd
CVE-2020-9247P3HIGHCVSS 7.8v9.1.0.272\(c635e4r2p2\)fixed in 10.1.0.123\(c432e22r2p5\)+5 more2020-12-07
CVE-2020-9247 [HIGH] CWE-120 CVE-2020-9247: There is a buffer overflow vulnerability in several Huawei products. The system does not sufficientl There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code executio
nvd
CVE-2020-1800P3HIGHCVSS 7.8fixed in 10.0.0.185\(c00e85r1p11\)2020-03-26
CVE-2020-1800 [HIGH] CVE-2020-1800: HUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access co HUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access control vulnerability. The software incorrectly restricts access to a function interface from an unauthorized actor, the attacker tricks the user into installing a crafted application, successful exploit could allow the attacker do certain unauthenticated operation
nvd
CVE-2020-9263P3HIGHCVSS 7.8fixed in 10.1.0.160\(c00e160r2p11\)2020-10-19
CVE-2020-9263 [HIGH] CWE-416 CVE-2020-9263: HUAWEI Mate 30 versions earlier than 10.1.0.150(C00E136R5P3) and HUAWEI P30 version earlier than 10. HUAWEI Mate 30 versions earlier than 10.1.0.150(C00E136R5P3) and HUAWEI P30 version earlier than 10.1.0.160(C00E160R2P11) have a use after free vulnerability. There is a condition exists that the system would reference memory after it has been freed, the attacker should trick the user into running a crafted application with common privilege, successful
nvd
CVE-2019-5225P3HIGHCVSS 7.8fixed in elle-al00b_9.1.0.193\(c00e190r1p21\)2019-11-29
CVE-2019-5225 [HIGH] CWE-120 CVE-2019-5225: P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E19 P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12) have a buffer overflow vulnerability on several , the system does not properly validate certain length parameter which an applicati
nvd
CVE-2019-5228P3HIGHCVSS 7.8fixed in elle-al00b_9.1.0.193\(c00e190r1p21\)2019-11-12
CVE-2019-5228 [HIGH] CWE-362 CVE-2019-5228: Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00 Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12), Versions earlier than Princeton-AL10B 9.1.0.233(C00E233R4P3) have a race condition vulnerability. The system does not lock certain function properly, when the function i
nvd
CVE-2020-9076P4MEDIUMCVSS 6.8fixed in 10.1.0.135\(c00e135r2p11\)2020-06-15
CVE-2020-9076 [MEDIUM] CWE-287 CVE-2020-9076: HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11) HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier than 10.1.0.135(C00E135R2P8), versions earlier than 10.1.0.135 have an improper authentication vulnerability. Due to the identity of the message sender not being properly verified, an attacker can exploit this vulnerability through ma
nvd
CVE-2021-22327P4MEDIUMCVSS 6.5v10.0.0.186\(c10e7r5p1\)v10.0.0.186\(c461e4r3p1\)+9 more2021-04-28
CVE-2021-22327 [MEDIUM] CWE-787 CVE-2021-22327: There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. Due to insufficient validation of the input files, successful exploit could cause certain service abnormal. Affected product versions include:HUAWEI P30 versions 10.0.0.186(C10E7R5P1), 10.0.0.186(C461E4R3P1), 10.0.0.188(C00E85R2P11), 10.0.0.188(C01E8
nvd
CVE-2020-1813P4MEDIUMCVSS 6.8fixed in 10.1.0.135\(c00e135r2p11\)2020-06-15
CVE-2020-1813 [MEDIUM] CWE-306 CVE-2020-1813: HUAWEI P30 smart phone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authenti HUAWEI P30 smart phone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. Due to improper authentication of specific interface, in specific scenario attackers could access specific interface without authentication. Successful exploit could allow the attacker to perform unauthorized operations.
nvd
CVE-2019-5215P4MEDIUMCVSS 6.8fixed in ele-al00_9.1.0.162\(c01e160r1p12\/c01e160r2p1\)2019-06-04
CVE-2019-5215 [MEDIUM] CVE-2019-5215: There is a man-in-the-middle (MITM) vulnerability on Huawei P30 smartphones versions before ELE-AL00 There is a man-in-the-middle (MITM) vulnerability on Huawei P30 smartphones versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), and P30 Pro versions before VOG-AL00 9.1.0.162 (C01E160R1P12/C01E160R2P1). When users establish connection and transfer data through Huawei Share, an attacker could sniff, spoof and do a series of operations to intrude the
nvd
CVE-2020-9244P4MEDIUMCVSS 6.8fixed in 10.1.0.160\(c00e160r2p11\)2020-08-11
CVE-2020-9244 [MEDIUM] CVE-2020-9244: HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Ve HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier than 10.1.0.270(C635E3R1P5),Versions earlier than 10.1.0.273(C636E7R2P4);HUAWEI Mate 20 X versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI P30 versions Versions earlier than 10.1.0.160(C00
nvd
CVE-2020-9081P4MEDIUMCVSS 6.8fixed in 10.1.0.160\(c00e160r2p11\)2024-12-27
CVE-2020-9081 [MEDIUM] CWE-285 CVE-2020-9081: There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perfo There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144) This vulnerability has been assigned a Common Vulnerabilities and Exposures
nvd
CVE-2020-9260P4MEDIUMCVSS 6.5fixed in 10.1.0.123\(c432e22r2p5\)2020-07-10
CVE-2020-9260 [MEDIUM] CVE-2020-9260: HUAWEI P30 and HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E22R2P5) and ver HUAWEI P30 and HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E22R2P5) and versions earlier than 10.1.0.160(C00E160R2P8) have an information disclosure vulnerability. Certain WI-FI function's default configuration in the system seems insecure, an attacker should craft a WI-FI hotspot to launch the attack. Successful exploit could cause i
nvd
CVE-2021-22330P4MEDIUMCVSS 6.5v9.1.0.131\(c00e130r1p21\)2021-04-28
CVE-2021-22330 [MEDIUM] CWE-787 CVE-2021-22330: There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00 There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when processing a message. An unauthenticated attacker can exploit this vulnerability by sending specific message to the target device. Due to insufficient validation of the input parameter, successful exploit can cause the process and the
nvd
Huawei P30 Firmware vulnerabilities | cvebase