Huawei P30 Pro Firmware vulnerabilities
28 known vulnerabilities affecting huawei/p30_pro_firmware.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM20LOW1
Vulnerabilities
Page 1 of 2
CVE-2020-0022P3HIGHCVSS 8.8fixed in 10.0.0.195\(c00e85r2p8\)2020-02-13
CVE-2020-0022 [HIGH] CWE-682 CVE-2020-0022: In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Andr
nvd
CVE-2020-9257P3HIGHCVSS 8.8fixed in 10.1.0.123\(c432e19r2p5patch02\)fixed in 10.1.0.126\(c10e11r5p1\)+1 more2020-07-17
CVE-2020-9257 [HIGH] CWE-120 CVE-2020-9257: HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earli
HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a buffer overflow vulnerability. The software access data past the end, or before the beginning, of the intended buffer when handling certain operations of certificate,
nvd
CVE-2020-9123P3HIGHCVSS 7.8fixed in 10.1.0.160\(c00e160r2p8\)fixed in 10.1.0.160\(c01e160r2p8\)2020-10-12
CVE-2020-9123 [HIGH] CWE-787 CVE-2020-9123: HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) and versions earlier than 10.1.0.160(C0
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) and versions earlier than 10.1.0.160(C01E160R2P8) have a buffer overflow vulnerability. An attacker induces users to install malicious applications and sends specially constructed packets to affected devices after obtaining the root permission. Successful exploit may cause code execution.
nvd
CVE-2020-9247P3HIGHCVSS 7.8fixed in 10.1.0.160\(c00e160r2p8\)2020-12-07
CVE-2020-9247 [HIGH] CWE-120 CVE-2020-9247: There is a buffer overflow vulnerability in several Huawei products. The system does not sufficientl
There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code executio
nvd
CVE-2019-5225P3HIGHCVSS 7.8fixed in vogue-al00a_9.1.0.193\(c00e190r1p12\)2019-11-29
CVE-2019-5225 [HIGH] CWE-120 CVE-2019-5225: P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E19
P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12) have a buffer overflow vulnerability on several , the system does not properly validate certain length parameter which an applicati
nvd
CVE-2019-5228P3HIGHCVSS 7.8fixed in vogue-al00a_9.1.0.193\(c00e190r1p12\)2019-11-12
CVE-2019-5228 [HIGH] CWE-362 CVE-2019-5228: Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00
Certain detection module of P30, P30 Pro, Honor V20 smartphone whith Versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), Versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12), Versions earlier than Princeton-AL10B 9.1.0.233(C00E233R4P3) have a race condition vulnerability. The system does not lock certain function properly, when the function i
nvd
CVE-2020-9254P3HIGHCVSS 7.8fixed in 10.1.0.123\(c432e19r2p5patch02\)fixed in 10.1.0.126\(c10e11r5p1\)+1 more2020-07-17
CVE-2020-9254 [HIGH] CWE-20 CVE-2020-9254: HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earli
HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a logic check error vulnerability. A logic error occurs when the software checking the size of certain parameter, the attacker should trick the user into installing a ma
nvd
CVE-2020-9076P4MEDIUMCVSS 6.8fixed in 10.1.0.135\(c00e135r2p8\)fixed in 10.1.0.135\(c01e135r2p8\)2020-06-15
CVE-2020-9076 [MEDIUM] CWE-287 CVE-2020-9076: HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11)
HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier than 10.1.0.135(C00E135R2P8), versions earlier than 10.1.0.135 have an improper authentication vulnerability. Due to the identity of the message sender not being properly verified, an attacker can exploit this vulnerability through ma
nvd
CVE-2019-5215P4MEDIUMCVSS 6.8fixed in vog-al00_9.1.0.162\(c01e160r1p12\/c01e160r2p1\)2019-06-04
CVE-2019-5215 [MEDIUM] CVE-2019-5215: There is a man-in-the-middle (MITM) vulnerability on Huawei P30 smartphones versions before ELE-AL00
There is a man-in-the-middle (MITM) vulnerability on Huawei P30 smartphones versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), and P30 Pro versions before VOG-AL00 9.1.0.162 (C01E160R1P12/C01E160R2P1). When users establish connection and transfer data through Huawei Share, an attacker could sniff, spoof and do a series of operations to intrude the
nvd
CVE-2020-9244P4MEDIUMCVSS 6.8fixed in 10.1.0.160\(c00e160r2p8\)2020-08-11
CVE-2020-9244 [MEDIUM] CVE-2020-9244: HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Ve
HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than 10.1.0.270(C431E7R1P5),Versions earlier than 10.1.0.270(C635E3R1P5),Versions earlier than 10.1.0.273(C636E7R2P4);HUAWEI Mate 20 X versions Versions earlier than 10.1.0.160(C00E160R2P8);HUAWEI P30 versions Versions earlier than 10.1.0.160(C00
nvd
CVE-2020-9081P4MEDIUMCVSS 6.8fixed in 10.1.0.160\(c00e160r2p8\)fixed in 10.1.0.160\(c01e160r2p8\)2024-12-27
CVE-2020-9081 [MEDIUM] CWE-285 CVE-2020-9081: There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perfo
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144)
This vulnerability has been assigned a Common Vulnerabilities and Exposures
nvd
CVE-2020-9260P4MEDIUMCVSS 6.5fixed in 10.1.0.160\(c00e160r2p8\)2020-07-10
CVE-2020-9260 [MEDIUM] CVE-2020-9260: HUAWEI P30 and HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E22R2P5) and ver
HUAWEI P30 and HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E22R2P5) and versions earlier than 10.1.0.160(C00E160R2P8) have an information disclosure vulnerability. Certain WI-FI function's default configuration in the system seems insecure, an attacker should craft a WI-FI hotspot to launch the attack. Successful exploit could cause i
nvd
CVE-2020-1836P4MEDIUMCVSS 5.3fixed in 10.1.0.160\(c00e160r2p8\)2020-07-06
CVE-2020-1836 [MEDIUM] CVE-2020-1836: HUAWEI P30 with versions earlier than 10.1.0.160(C00E160R2P11) and HUAWEI P30 Pro with versions earl
HUAWEI P30 with versions earlier than 10.1.0.160(C00E160R2P11) and HUAWEI P30 Pro with versions earlier than 10.1.0.160(C00E160R2P8) have an information disclosure vulnerability. Certain function's default configuration in the system seems insecure, an attacker should craft a WI-FI hotspot to launch the attack. Successful exploit could cause information discl
nvd
CVE-2019-5251P4MEDIUMCVSS 5.5fixed in 9.1.0.226\(c00e210r2p1\)2019-12-13
CVE-2019-5251 [MEDIUM] CWE-22 CVE-2019-5251: There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficien
There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain pathnames from the application. An attacker could trick the user into installing, backing up and restoring a malicious application. Successful exploit could cause information disclosure.
nvd
CVE-2020-9107P4MEDIUMCVSS 5.5fixed in 10.1.0.160\(c00e160r2p8\)2020-10-12
CVE-2020-9107 [MEDIUM] CWE-125 CVE-2020-9107: HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vu
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the process reboot.
nvd
CVE-2020-9108P4MEDIUMCVSS 5.5fixed in 10.1.0.160\(c00e160r2p8\)2020-10-12
CVE-2020-9108 [MEDIUM] CWE-125 CVE-2020-9108: HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vu
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the process reboot.
nvd
CVE-2019-5226P4MEDIUMCVSS 5.5fixed in vogue-al00a_9.1.0.193\(c00e190r2p1\)2019-11-29
CVE-2019-5226 [MEDIUM] CWE-346 CVE-2019-5226: P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E19
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do
nvd
CVE-2019-5227P4MEDIUMCVSS 5.5fixed in vogue-al00a_9.1.0.193\(c00e190r2p1\)2019-11-29
CVE-2019-5227 [MEDIUM] CWE-346 CVE-2019-5227: P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E19
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability. The device and HiSuite software do
nvd
CVE-2020-9095P4MEDIUMCVSS 5.5fixed in 10.1.0.160\(c00e160r2p8\)2020-08-21
CVE-2020-9095 [MEDIUM] CWE-190 CVE-2020-9095: HUAWEI P30 Pro smartphone with Versions earlier than 10.1.0.160(C00E160R2P8) has an integer overflow
HUAWEI P30 Pro smartphone with Versions earlier than 10.1.0.160(C00E160R2P8) has an integer overflow vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause integer overflow. This can compromise normal service.
nvd
CVE-2019-5302P4MEDIUMCVSS 5.3fixed in 9.1.0.186\(c00e180r2p1\)2020-04-27
CVE-2019-5302 [MEDIUM] CWE-20 CVE-2019-5302: There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send spe
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1 out of 2 vulnerabilities. Different
nvd
1 / 2Next →