Huawei P30 Firmware vulnerabilities
42 known vulnerabilities affecting huawei/p30_firmware.
Total CVEs
42
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH12MEDIUM27LOW3
Vulnerabilities
Page 2 of 3
CVE-2019-19441P4MEDIUMCVSS 6.5fixed in 10.0.0.166\(c00e66r1p11\)2020-01-03
CVE-2019-19441 [MEDIUM] CVE-2019-19441: HUAWEI P30 smart phones with versions earlier than 10.0.0.166(C00E66R1P11) have an information leak
HUAWEI P30 smart phones with versions earlier than 10.0.0.166(C00E66R1P11) have an information leak vulnerability. An attacker could send specific command in the local area network (LAN) to exploit this vulnerability. Successful exploitation may cause information leak.
nvd
CVE-2019-5229P4MEDIUMCVSS 6.2fixed in elle-al00b_9.1.0.193\(c00e190r2p1\)vVersions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1)2019-11-12
CVE-2019-5229 [MEDIUM] CWE-345 CVE-2019-5229: P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient ve
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient verification vulnerability. The system does not verify certain parameters sufficiently, an attacker should connect to the phone and gain high privilege to launch the attack, successful exploit could cause malicious code execution.
nvd
CVE-2019-5224P4MEDIUMCVSS 5.5fixed in elle-al00b_9.1.0.193\(c00e190r1p21\)vVersions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21)2019-11-29
CVE-2019-5224 [MEDIUM] CWE-125 CVE-2019-5224: P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) have an out of bounds
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) have an out of bounds read vulnerability. The system does not properly validate certain length parameter which an application transports to kernel. An attacker tricks the user to install a malicious application, successful exploit could cause out of bounds read and informatio
nvd
CVE-2020-1836P4MEDIUMCVSS 5.3fixed in 10.1.0.160\(c00e160r2p11\)2020-07-06
CVE-2020-1836 [MEDIUM] CVE-2020-1836: HUAWEI P30 with versions earlier than 10.1.0.160(C00E160R2P11) and HUAWEI P30 Pro with versions earl
HUAWEI P30 with versions earlier than 10.1.0.160(C00E160R2P11) and HUAWEI P30 Pro with versions earlier than 10.1.0.160(C00E160R2P8) have an information disclosure vulnerability. Certain function's default configuration in the system seems insecure, an attacker should craft a WI-FI hotspot to launch the attack. Successful exploit could cause information discl
nvd
CVE-2020-9249P4MEDIUMCVSS 6.5fixed in 10.1.0.160\(c00e160r2p11\)2020-07-31
CVE-2020-9249 [MEDIUM] CWE-401 CVE-2020-9249: HUAWEI P30 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have a denial of service
HUAWEI P30 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have a denial of service vulnerability. A module does not deal with mal-crafted messages and it leads to memory leak. Attackers can exploit this vulnerability to make the device denial of service.Affected product versions include: HUAWEI P30 versions Versions earlier than 10.1.0
nvd
CVE-2020-9226P4MEDIUMCVSS 5.5fixed in 10.1.0.135\(c00e135r2p11\)2020-07-06
CVE-2020-9226 [MEDIUM] CWE-347 CVE-2020-9226: HUAWEI P30 with versions earlier than 10.1.0.135(C00E135R2P11) have an improper signature verificati
HUAWEI P30 with versions earlier than 10.1.0.135(C00E135R2P11) have an improper signature verification vulnerability. The system does not improper check signature of specific software package, an attacker may exploit this vulnerability to load a crafted software package to the device.
nvd
CVE-2019-5251P4MEDIUMCVSS 5.5fixed in 9.1.0.226\(c00e220r2p1\)2019-12-13
CVE-2019-5251 [MEDIUM] CWE-22 CVE-2019-5251: There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficien
There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.
nvd
CVE-2019-5226P4MEDIUMCVSS 5.5fixed in elle-al00b_9.1.0.193\(c00e190r2p1\)2019-11-29
CVE-2019-5226 [MEDIUM] CWE-346 CVE-2019-5226: P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E19
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do
nvd
CVE-2019-5227P4MEDIUMCVSS 5.5fixed in elle-al00b_9.1.0.193\(c00e190r2p1\)2019-11-29
CVE-2019-5227 [MEDIUM] CWE-346 CVE-2019-5227: P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E19
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do
nvd
CVE-2020-9258P4MEDIUMCVSS 5.5fixed in 10.1.0.135\(c00e135r2p11\)2020-07-10
CVE-2020-9258 [MEDIUM] CWE-20 CVE-2020-9258: HUAWEI P30 smartphone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper input ver
HUAWEI P30 smartphone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper input verification vulnerability. An attribution in a module is not set correctly and some verification is lacked. Attackers with local access can exploit this vulnerability by injecting malicious fragment. This may lead to user information leak.
nvd
CVE-2021-22399P4MEDIUMCVSS 5.5v10.0.0.195\(c432e22r2p5\)v10.0.0.200\(c00e85r2p11\)+7 more2021-07-13
CVE-2021-22399 [MEDIUM] CVE-2021-22399: The Bluetooth function of some Huawei smartphones has a DoS vulnerability. Attackers can install thi
The Bluetooth function of some Huawei smartphones has a DoS vulnerability. Attackers can install third-party apps to send specific broadcasts, causing the Bluetooth module to crash. This vulnerability is successfully exploited to cause the Bluetooth function to become abnormal. Affected product versions include: HUAWEI P30 10.0.0.195(C432E22R2P5), 10.0.0.20
nvd
CVE-2019-5302P4MEDIUMCVSS 5.3fixed in 9.1.0.1932020-04-27
CVE-2019-5302 [MEDIUM] CWE-20 CVE-2019-5302: There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send spe
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1 out of 2 vulnerabilities. Different
nvd
CVE-2019-5303P4MEDIUMCVSS 5.3fixed in 9.1.0.1932020-04-27
CVE-2019-5303 [MEDIUM] CWE-20 CVE-2019-5303: There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send spe
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 2 out of 2 vulnerabilities. Different
nvd
CVE-2020-9245P4MEDIUMCVSS 5.5fixed in 10.1.0.160\(c00e160r2p11\)2020-08-10
CVE-2020-9245 [MEDIUM] CVE-2020-9245: HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions
HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0.160(C00E160R2P8) have a denial of service vulnerability. Certain system configuration can be modified because of improper authorization. The attacker could trick the user installing and executing a malicious application, successful exploit co
nvd
CVE-2020-1798P4MEDIUMCVSS 4.6fixed in 10.1.0.135\(c00e135r2p11\)2020-05-29
CVE-2020-1798 [MEDIUM] CWE-287 CVE-2020-1798: HUAWEI P30 smartphones with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authenti
HUAWEI P30 smartphones with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. A logic error occurs when handling NFC work, an attacker should establish a NFC connection to the target phone, and then do a series of operations on the target phone. Successful exploit could allow a guest user do certain operatio
nvd
CVE-2019-5231P4MEDIUMCVSS 4.6fixed in elle-al00b_9.1.0.186\(c00e180r2p1\)vVersions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1)2019-11-13
CVE-2019-5231 [MEDIUM] CWE-863 CVE-2019-5231: P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper author
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check when a user attempts to perform certain action. Successful exploit could allow the attacker to update a crafted package.
nvd
CVE-2020-1834P4MEDIUMCVSS 4.6fixed in 10.1.0.135\(c00e135r2p11\)2020-06-18
CVE-2020-1834 [MEDIUM] CWE-354 CVE-2020-1834: HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earli
HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earlier than 10.1.0.135(C00E135R2P8) have an insufficient integrity check vulnerability. The system does not check certain software package's integrity sufficiently. Successful exploit could allow an attacker to load a crafted software package to the device.
nvd
CVE-2020-9104P4MEDIUMCVSS 4.3fixed in 10.1.0.123\(c431e22r2p5\)fixed in 10.1.0.123\(c432e22r2p5\)+8 more2020-08-21
CVE-2020-9104 [MEDIUM] CWE-401 CVE-2020-9104: HUAWEI P30 smartphones with Versions earlier than 10.1.0.123(C431E22R2P5),Versions earlier than 10.1
HUAWEI P30 smartphones with Versions earlier than 10.1.0.123(C431E22R2P5),Versions earlier than 10.1.0.123(C432E22R2P5),Versions earlier than 10.1.0.126(C10E7R5P1),Versions earlier than 10.1.0.126(C185E4R7P1),Versions earlier than 10.1.0.126(C461E7R3P1),Versions earlier than 10.1.0.126(C605E19R1P3),Versions earlier than 10.1.0.126(C636E7R3P4),Versions
nvd
CVE-2019-5307P4MEDIUMCVSS 4.2fixed in ele-al00_9.1.0.1622019-06-04
CVE-2019-5307 [MEDIUM] CWE-294 CVE-2019-5307: Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30
Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Pro versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), are exposed to a message replay vulnerability. For the sake of better compatibility, these devices implement a less strict check on the NAS message sequence number (SN), specifically NAS
nvd
CVE-2020-9077P4LOWCVSS 3.3fixed in 10.1.0.160\(c00e160r2p11\)2020-07-27
CVE-2020-9077 [LOW] CWE-287 CVE-2020-9077: HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information expo
HUAWEI P30 smart phones with versions earlier than 10.1.0.160(C00E160R2P11) have an information exposure vulnerability. The system does not properly authenticate the application that access a specified interface. Attackers can trick users into installing malicious software to exploit this vulnerability and obtain some information about the device. Succes
nvd