Huawei P30 Firmware vulnerabilities
42 known vulnerabilities affecting huawei/p30_firmware.
Total CVEs
42
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH12MEDIUM27LOW3
Vulnerabilities
Page 2 of 3
CVE-2020-9076MEDIUMCVSS 6.8fixed in 10.1.0.135\(c00e135r2p11\)2020-06-15
CVE-2020-9076 [MEDIUM] CWE-287 CVE-2020-9076: HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11)
HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier than 10.1.0.135(C00E135R2P8), versions earlier than 10.1.0.135 have an improper authentication vulnerability. Due to the identity of the message sender not being properly verified, an attacker can exploit this vulnerability through ma
nvd
CVE-2020-1798MEDIUMCVSS 4.6fixed in 10.1.0.135\(c00e135r2p11\)2020-05-29
CVE-2020-1798 [MEDIUM] CWE-287 CVE-2020-1798: HUAWEI P30 smartphones with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authenti
HUAWEI P30 smartphones with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. A logic error occurs when handling NFC work, an attacker should establish a NFC connection to the target phone, and then do a series of operations on the target phone. Successful exploit could allow a guest user do certain operatio
nvd
CVE-2019-5302MEDIUMCVSS 5.3fixed in 9.1.0.1932020-04-27
CVE-2019-5302 [MEDIUM] CWE-20 CVE-2019-5302: There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send spe
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1 out of 2 vulnerabilities. Different
nvd
CVE-2019-5303MEDIUMCVSS 5.3fixed in 9.1.0.1932020-04-27
CVE-2019-5303 [MEDIUM] CWE-20 CVE-2019-5303: There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send spe
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 2 out of 2 vulnerabilities. Different
nvd
CVE-2020-1800HIGHCVSS 7.8fixed in 10.0.0.185\(c00e85r1p11\)2020-03-26
CVE-2020-1800 [HIGH] CVE-2020-1800: HUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access co
HUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access control vulnerability. The software incorrectly restricts access to a function interface from an unauthorized actor, the attacker tricks the user into installing a crafted application, successful exploit could allow the attacker do certain unauthenticated operation
nvd
CVE-2020-1812HIGHCVSS 7.8fixed in 10.0.0.173\(c00e73r1p11\)2020-02-18
CVE-2020-1812 [HIGH] CWE-287 CVE-2020-1812: HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentic
HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentication vulnerability. Due to improperly validation of certain application, an attacker should trick the user into installing a malicious application to exploit this vulnerability. Successful exploit could allow the attacker to bypass the authentication to
nvd
CVE-2020-0022HIGHCVSS 8.8fixed in 10.0.0.190\(c432e22r2p5\)2020-02-13
CVE-2020-0022 [HIGH] CWE-682 CVE-2020-0022: In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Andr
nvd
CVE-2019-19441MEDIUMCVSS 6.5fixed in 10.0.0.166\(c00e66r1p11\)2020-01-03
CVE-2019-19441 [MEDIUM] CVE-2019-19441: HUAWEI P30 smart phones with versions earlier than 10.0.0.166(C00E66R1P11) have an information leak
HUAWEI P30 smart phones with versions earlier than 10.0.0.166(C00E66R1P11) have an information leak vulnerability. An attacker could send specific command in the local area network (LAN) to exploit this vulnerability. Successful exploitation may cause information leak.
nvd
CVE-2019-5265HIGHCVSS 7.5v9.1.0.193\(c00e190r2p1\)2019-12-23
CVE-2019-5265 [HIGH] CVE-2019-5265: Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an improper access control vulner
Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an improper access control vulnerability. The function incorrectly controls certain access messages, attackers can simulate a sender to steal P2P network information. Successful exploit may cause information leakage.
nvd
CVE-2019-5266HIGHCVSS 7.5v9.1.0.193\(c00e190r2p1\)2019-12-23
CVE-2019-5266 [HIGH] CWE-20 CVE-2019-5266: Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation
Huawei Share function in P30 9.1.0.193(C00E190R2P1) smartphone has an insufficient input validation vulnerability. Attackers can exploit this vulnerability by sending crafted packets to the affected device. Successful exploit may cause the function will be disabled.
nvd
CVE-2019-5251MEDIUMCVSS 5.5fixed in 9.1.0.226\(c00e220r2p1\)2019-12-13
CVE-2019-5251 [MEDIUM] CWE-22 CVE-2019-5251: There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficien
There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.
nvd
CVE-2019-5225HIGHCVSS 7.8fixed in elle-al00b_9.1.0.193\(c00e190r1p21\)2019-11-29
CVE-2019-5225 [HIGH] CWE-120 CVE-2019-5225: P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E19
P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12) have a buffer overflow vulnerability on several , the system does not properly validate certain length parameter which an applicati
nvd
CVE-2019-5224MEDIUMCVSS 5.5fixed in elle-al00b_9.1.0.193\(c00e190r1p21\)2019-11-29
CVE-2019-5224 [MEDIUM] CWE-125 CVE-2019-5224: P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) have an out of bounds
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) have an out of bounds read vulnerability. The system does not properly validate certain length parameter which an application transports to kernel. An attacker tricks the user to install a malicious application, successful exploit could cause out of bounds read and informatio
nvd
CVE-2019-5226MEDIUMCVSS 5.5fixed in elle-al00b_9.1.0.193\(c00e190r2p1\)2019-11-29
CVE-2019-5226 [MEDIUM] CWE-346 CVE-2019-5226: P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E19
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do
nvd
CVE-2019-5227MEDIUMCVSS 5.5fixed in elle-al00b_9.1.0.193\(c00e190r2p1\)2019-11-29
CVE-2019-5227 [MEDIUM] CWE-346 CVE-2019-5227: P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E19
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do
nvd
CVE-2019-5288HIGHCVSS 7.8fixed in elle-al00b_9.1.0.193\(c00e190r2p1\)2019-11-13
CVE-2019-5288 [HIGH] CWE-190 CVE-2019-5288: P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overfl
P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due to insufficient check on specific parameters. An attacker tricks the user into installing a malicious application, obtains the root permission and constructs specific parameters to the camera program to exploit this vulnerability. Suc
nvd
CVE-2019-5287HIGHCVSS 7.8fixed in elle-al00b_9.1.0.193\(c00e190r2p1\)2019-11-13
CVE-2019-5287 [HIGH] CWE-190 CVE-2019-5287: P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overfl
P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due to insufficient check on specific parameters. An attacker tricks the user into installing a malicious application, obtains the root permission and constructs specific parameters to the camera program to exploit this vulnerability. Suc
nvd
CVE-2019-5231MEDIUMCVSS 4.6fixed in elle-al00b_9.1.0.186\(c00e180r2p1\)2019-11-13
CVE-2019-5231 [MEDIUM] CWE-863 CVE-2019-5231: P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper author
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check when a user attempts to perform certain action. Successful exploit could allow the attacker to update a crafted package.
nvd
CVE-2019-5228HIGHCVSS 7.8fixed in elle-al00b_9.1.0.193\(c00e190r1p21\)2019-11-12
CVE-2019-5228 [HIGH] CWE-362 CVE-2019-5228: Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00
Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12), Versions earlier than Princeton-AL10B 9.1.0.233(C00E233R4P3) have a race condition vulnerability. The system does not lock certain function properly, when the function i
nvd
CVE-2019-5229MEDIUMCVSS 6.2fixed in elle-al00b_9.1.0.193\(c00e190r2p1\)2019-11-12
CVE-2019-5229 [MEDIUM] CWE-345 CVE-2019-5229: P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient ve
P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an insufficient verification vulnerability. The system does not verify certain parameters sufficiently, an attacker should connect to the phone and gain high privilege to launch the attack, successful exploit could cause malicious code execution.
nvd