cbcvebase.

Huawei P30 Pro Firmware vulnerabilities

28 known vulnerabilities affecting huawei/p30_pro_firmware.

Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM20LOW1

Vulnerabilities

Page 2 of 2
CVE-2019-5303P4MEDIUMCVSS 5.3fixed in 9.1.0.186\(c00e180r2p1\)2020-04-27
CVE-2019-5303 [MEDIUM] CWE-20 CVE-2019-5303: There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send spe There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 2 out of 2 vulnerabilities. Different
nvd
CVE-2020-9096P4MEDIUMCVSS 5.5fixed in 10.1.0.160\(c00e160r2p8\)2020-08-21
CVE-2020-9096 [MEDIUM] CWE-125 CVE-2020-9096: HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound r HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.
nvd
CVE-2020-9245P4MEDIUMCVSS 5.5fixed in 10.1.0.160\(c00e160r2p8\)2020-08-10
CVE-2020-9245 [MEDIUM] CVE-2020-9245: HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11);HUAWEI P30 Pro versions Versions earlier than 10.1.0.160(C00E160R2P8) have a denial of service vulnerability. Certain system configuration can be modified because of improper authorization. The attacker could trick the user installing and executing a malicious application, successful exploit co
nvd
CVE-2020-9109P4MEDIUMCVSS 4.6fixed in 10.1.0.160\(c00e160r2p8\)2020-10-12
CVE-2020-9109 [MEDIUM] CWE-287 CVE-2020-9109: There is an information disclosure vulnerability in several smartphones. The device does not suffici There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker need to gain certain information in the victim's smartphone to launch the attack, and successful exploit could cause information disclosure.Affected product
nvd
CVE-2020-9106P4MEDIUMCVSS 4.6fixed in 10.1.0.160\(c00e160r2p8\)2020-10-12
CVE-2020-9106 [MEDIUM] CWE-22 CVE-2020-9106: HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. Th HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. The system does not sufficiently validate certain pathname, successful exploit could allow the attacker access files and cause information disclosure.
nvd
CVE-2020-1834P4MEDIUMCVSS 4.6fixed in 10.1.0.135\(c00e135r2p8\)2020-06-18
CVE-2020-1834 [MEDIUM] CWE-354 CVE-2020-1834: HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earli HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earlier than 10.1.0.135(C00E135R2P8) have an insufficient integrity check vulnerability. The system does not check certain software package's integrity sufficiently. Successful exploit could allow an attacker to load a crafted software package to the device.
nvd
CVE-2019-5307P4MEDIUMCVSS 4.2fixed in vog-al00_9.1.0.1622019-06-04
CVE-2019-5307 [MEDIUM] CWE-294 CVE-2019-5307: Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Some Huawei 4G LTE devices, P30 versions before ELE-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1) and P30 Pro versions before VOG-AL00 9.1.0.162(C01E160R1P12/C01E160R2P1), are exposed to a message replay vulnerability. For the sake of better compatibility, these devices implement a less strict check on the NAS message sequence number (SN), specifically NAS
nvd
CVE-2020-9089P4LOWCVSS 3.3fixed in 10.1.0.120\(c431e19r2p5\)fixed in 10.1.0.120\(c432e19r2p5\)+2 more2024-12-27
CVE-2020-9089 [LOW] CWE-200 CVE-2020-9089: There is an information vulnerability in Huawei smartphones. A function in a module can be called wi There is an information vulnerability in Huawei smartphones. A function in a module can be called without verifying the caller's access. Attackers with user access can exploit this vulnerability to obtain some information. This can lead to information leak. (Vulnerability ID: HWPSIRT-2019-12141) This vulnerability has been assigned a Common Vulnerabilit
nvd
Huawei P30 Pro Firmware vulnerabilities | cvebase