Huawei Taurus-Al00B Firmware vulnerabilities

4 known vulnerabilities affecting huawei/taurus-al00b_firmware.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2020-9237MEDIUMCVSS 6.7fixed in 10.1.0.126\(c00e125r5p3\)vVersions earlier than 10.1.0.126(C00E125R5P3)2020-08-17
CVE-2020-9237 [MEDIUM] CWE-416 CVE-2020-9237: Huawei smartphone Taurus-AL00B with versions earlier than 10.1.0.126(C00E125R5P3) have a user after Huawei smartphone Taurus-AL00B with versions earlier than 10.1.0.126(C00E125R5P3) have a user after free vulnerability. A module is lack of lock protection. Attackers can exploit this vulnerability by launching specific request. This could compromise normal service of the affected device.
cvelistv5nvd
CVE-2020-9070MEDIUMCVSS 5.5fixed in 10.0.0.205\(c00e201r7p2\)2020-04-20
CVE-2020-9070 [MEDIUM] CWE-287 CVE-2020-9070: Huawei smartphones Taurus-AL00B with versions earlier than 10.0.0.205(C00E201R7P2) have an improper Huawei smartphones Taurus-AL00B with versions earlier than 10.0.0.205(C00E201R7P2) have an improper authentication vulnerability. The software insufficiently validate the user's identity when a user wants to do certain operation. An attacker can trick user into installing a malicious application to exploit this vulnerability. Successful exploit may cau
nvd
CVE-2020-9065MEDIUMCVSS 5.5fixed in 10.0.0.203\(c00e201r7p2\)vVersions earlier than 10.0.0.203(C00E201R7P2)2020-03-26
CVE-2020-9065 [MEDIUM] CWE-416 CVE-2020-9065: Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after- Huawei smart phone Taurus-AL00B with versions earlier than 10.0.0.203(C00E201R7P2) have a use-after-free (UAF) vulnerability. An authenticated, local attacker may perform specific operations to exploit this vulnerability. Successful exploitation may tamper with the information to affect the availability.
cvelistv5nvd
CVE-2019-5233HIGHCVSS 8.8≤ 10.0.0.41\(sp2c00e41r3p2\)v10.0.0.41(SP2C00E41R3P2)2019-11-13
CVE-2019-5233 [HIGH] CWE-287 CVE-2019-5233: Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper Huawei smartphones with versions earlier than Taurus-AL00B 10.0.0.41(SP2C00E41R3P2) have an improper authentication vulnerability. Successful exploitation may cause the attacker to access specific components.
cvelistv5nvd