Huawei P30 Pro Firmware vulnerabilities
28 known vulnerabilities affecting huawei/p30_pro_firmware.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM20LOW1
Vulnerabilities
Page 1 of 2
CVE-2020-9081MEDIUMCVSS 6.8fixed in 10.1.0.160\(c00e160r2p8\)fixed in 10.1.0.160\(c01e160r2p8\)2024-12-27
CVE-2020-9081 [LOW] CWE-285 CVE-2020-9081: There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perfo
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144)
This vulnerability has been assigned a Common Vulnerabilities and Exposures (C
nvd
CVE-2020-9089LOWCVSS 3.3fixed in 10.1.0.120\(c431e19r2p5\)fixed in 10.1.0.120\(c432e19r2p5\)+2 more2024-12-27
CVE-2020-9089 [LOW] CWE-200 CVE-2020-9089: There is an information vulnerability in Huawei smartphones. A function in a module can be called wi
There is an information vulnerability in Huawei smartphones. A function in a module can be called without verifying the caller's access. Attackers with user access can exploit this vulnerability to obtain some information. This can lead to information leak. (Vulnerability ID: HWPSIRT-2019-12141)
This vulnerability has been assigned a Common Vulnerabilit
nvd
CVE-2020-9247HIGHCVSS 7.8fixed in 10.1.0.160\(c00e160r2p8\)2020-12-07
CVE-2020-9247 [HIGH] CWE-120 CVE-2020-9247: There is a buffer overflow vulnerability in several Huawei products. The system does not sufficientl
There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code executio
nvd
CVE-2020-9123HIGHCVSS 7.8fixed in 10.1.0.160\(c00e160r2p8\)fixed in 10.1.0.160\(c01e160r2p8\)2020-10-12
CVE-2020-9123 [HIGH] CWE-787 CVE-2020-9123: HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) and versions earlier than 10.1.0.160(C0
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) and versions earlier than 10.1.0.160(C01E160R2P8) have a buffer overflow vulnerability. An attacker induces users to install malicious applications and sends specially constructed packets to affected devices after obtaining the root permission. Successful exploit may cause code execution.
nvd
CVE-2020-9107MEDIUMCVSS 5.5fixed in 10.1.0.160\(c00e160r2p8\)2020-10-12
CVE-2020-9107 [MEDIUM] CWE-125 CVE-2020-9107: HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vu
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the process reboot.
nvd
CVE-2020-9109MEDIUMCVSS 4.6fixed in 10.1.0.160\(c00e160r2p8\)2020-10-12
CVE-2020-9109 [MEDIUM] CWE-287 CVE-2020-9109: There is an information disclosure vulnerability in several smartphones. The device does not suffici
There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker need to gain certain information in the victim's smartphone to launch the attack, and successful exploit could cause information disclosure.Affected product
nvd
CVE-2020-9106MEDIUMCVSS 4.6fixed in 10.1.0.160\(c00e160r2p8\)2020-10-12
CVE-2020-9106 [MEDIUM] CWE-22 CVE-2020-9106: HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. Th
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. The system does not sufficiently validate certain pathname, successful exploit could allow the attacker access files and cause information disclosure.
nvd
CVE-2020-9108MEDIUMCVSS 5.5fixed in 10.1.0.160\(c00e160r2p8\)2020-10-12
CVE-2020-9108 [MEDIUM] CWE-125 CVE-2020-9108: HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vu
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the process reboot.
nvd
CVE-2020-9095MEDIUMCVSS 5.5fixed in 10.1.0.160\(c00e160r2p8\)2020-08-21
CVE-2020-9095 [MEDIUM] CWE-190 CVE-2020-9095: HUAWEI P30 Pro smartphone with Versions earlier than 10.1.0.160(C00E160R2P8) has an integer overflow
HUAWEI P30 Pro smartphone with Versions earlier than 10.1.0.160(C00E160R2P8) has an integer overflow vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause integer overflow. This can compromise normal service.
nvd
CVE-2020-9096MEDIUMCVSS 5.5fixed in 10.1.0.160\(c00e160r2p8\)2020-08-21
CVE-2020-9096 [MEDIUM] CWE-125 CVE-2020-9096: HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound r
HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.
nvd
CVE-2020-9244MEDIUMCVSS 6.8fixed in 10.1.0.160\(c00e160r2p8\)2020-08-11
CVE-2020-9244 [MEDIUM] CVE-2020-9244: HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Ve
HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier than 10.1.0.270(C635E3R1P5),Versions earlier than 10.1.0.273(C636E7R2P4);HUAWEI Mate 20 X versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI P30 versions Versions earlier than 10.1.0.160(C00
nvd
CVE-2020-9245MEDIUMCVSS 5.5fixed in 10.1.0.160\(c00e160r2p8\)2020-08-10
CVE-2020-9245 [MEDIUM] CVE-2020-9245: HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions
HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0.160(C00E160R2P8) have a denial of service vulnerability. Certain system configuration can be modified because of improper authorization. The attacker could trick the user installing and executing a malicious application, successful exploit co
nvd
CVE-2020-9254HIGHCVSS 7.8fixed in 10.1.0.123\(c432e19r2p5patch02\)fixed in 10.1.0.126\(c10e11r5p1\)+1 more2020-07-17
CVE-2020-9254 [HIGH] CWE-20 CVE-2020-9254: HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earli
HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a logic check error vulnerability. A logic error occurs when the software checking the size of certain parameter, the attacker should trick the user into installing a ma
nvd
CVE-2020-9257HIGHCVSS 8.8fixed in 10.1.0.123\(c432e19r2p5patch02\)fixed in 10.1.0.126\(c10e11r5p1\)+1 more2020-07-17
CVE-2020-9257 [HIGH] CWE-120 CVE-2020-9257: HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earli
HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a buffer overflow vulnerability. The software access data past the end, or before the beginning, of the intended buffer when handling certain operations of certificate,
nvd
CVE-2020-9260MEDIUMCVSS 6.5fixed in 10.1.0.160\(c00e160r2p8\)2020-07-10
CVE-2020-9260 [MEDIUM] CVE-2020-9260: HUAWEI P30 and HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E22R2P5) and ver
HUAWEI P30 and HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E22R2P5) and versions earlier than 10.1.0.160(C00E160R2P8) have an information disclosure vulnerability. Certain WI-FI function's default configuration in the system seems insecure, an attacker should craft a WI-FI hotspot to launch the attack. Successful exploit could cause i
nvd
CVE-2020-1836MEDIUMCVSS 5.3fixed in 10.1.0.160\(c00e160r2p8\)2020-07-06
CVE-2020-1836 [MEDIUM] CVE-2020-1836: HUAWEI P30 with versions earlier than 10.1.0.160(C00E160R2P11) and HUAWEI P30 Pro with versions earl
HUAWEI P30 with versions earlier than 10.1.0.160(C00E160R2P11) and HUAWEI P30 Pro with versions earlier than 10.1.0.160(C00E160R2P8) have an information disclosure vulnerability. Certain function's default configuration in the system seems insecure, an attacker should craft a WI-FI hotspot to launch the attack. Successful exploit could cause information discl
nvd
CVE-2020-1834MEDIUMCVSS 4.6fixed in 10.1.0.135\(c00e135r2p8\)2020-06-18
CVE-2020-1834 [MEDIUM] CWE-354 CVE-2020-1834: HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earli
HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earlier than 10.1.0.135(C00E135R2P8) have an insufficient integrity check vulnerability. The system does not check certain software package's integrity sufficiently. Successful exploit could allow an attacker to load a crafted software package to the device.
nvd
CVE-2020-9076MEDIUMCVSS 6.8fixed in 10.1.0.135\(c00e135r2p8\)fixed in 10.1.0.135\(c01e135r2p8\)2020-06-15
CVE-2020-9076 [MEDIUM] CWE-287 CVE-2020-9076: HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11)
HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier than 10.1.0.135(C00E135R2P8), versions earlier than 10.1.0.135 have an improper authentication vulnerability. Due to the identity of the message sender not being properly verified, an attacker can exploit this vulnerability through ma
nvd
CVE-2019-5302MEDIUMCVSS 5.3fixed in 9.1.0.186\(c00e180r2p1\)2020-04-27
CVE-2019-5302 [MEDIUM] CWE-20 CVE-2019-5302: There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send spe
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1 out of 2 vulnerabilities. Different
nvd
CVE-2019-5303MEDIUMCVSS 5.3fixed in 9.1.0.186\(c00e180r2p1\)2020-04-27
CVE-2019-5303 [MEDIUM] CWE-20 CVE-2019-5303: There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send spe
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 2 out of 2 vulnerabilities. Different
nvd
1 / 2Next →