ID

VAR-202006-0974


CVE

CVE-2020-1813


TITLE

HUAWEI P30 Authentication vulnerabilities in smartphones

Trust: 0.8

sources: JVNDB: JVNDB-2020-006725

DESCRIPTION

HUAWEI P30 smart phone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper authentication vulnerability. Due to improper authentication of specific interface, in specific scenario attackers could access specific interface without authentication. Successful exploit could allow the attacker to perform unauthorized operations. HUAWEI P30 Smartphones contain authentication vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state

Trust: 1.62

sources: NVD: CVE-2020-1813 // JVNDB: JVNDB-2020-006725

AFFECTED PRODUCTS

vendor:huaweimodel:p30scope:ltversion:10.1.0.135\(c00e135r2p11\)

Trust: 1.0

vendor:huaweimodel:p30scope:eqversion:10.1.0.135(c00e135r2p11)

Trust: 0.8

sources: JVNDB: JVNDB-2020-006725 // NVD: CVE-2020-1813

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-1813
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-006725
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202002-746
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-1813
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-006725
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

nvd@nist.gov: CVE-2020-1813
baseSeverity: MEDIUM
baseScore: 6.8
vectorString: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-006725
baseSeverity: MEDIUM
baseScore: 6.8
vectorString: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2020-006725 // CNNVD: CNNVD-202002-746 // NVD: CVE-2020-1813

PROBLEMTYPE DATA

problemtype:CWE-306

Trust: 1.0

problemtype:CWE-287

Trust: 0.8

sources: JVNDB: JVNDB-2020-006725 // NVD: CVE-2020-1813

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202002-746

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-006725

PATCH

title:huawei-sa-20200610-04-smartphoneurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200610-04-smartphone-en

Trust: 0.8

title:Huawei NIP6800 , Secospace USG6600 and USG9500 Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=108180

Trust: 0.6

sources: JVNDB: JVNDB-2020-006725 // CNNVD: CNNVD-202002-746

EXTERNAL IDS

db:NVDid:CVE-2020-1813

Trust: 2.4

db:JVNDBid:JVNDB-2020-006725

Trust: 0.8

db:CNNVDid:CNNVD-202002-746

Trust: 0.6

sources: JVNDB: JVNDB-2020-006725 // CNNVD: CNNVD-202002-746 // NVD: CVE-2020-1813

REFERENCES

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200610-04-smartphone-en

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-1813

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-1813

Trust: 0.8

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20200212-02-firewall-cn

Trust: 0.6

sources: JVNDB: JVNDB-2020-006725 // CNNVD: CNNVD-202002-746 // NVD: CVE-2020-1813

SOURCES

db:JVNDBid:JVNDB-2020-006725
db:CNNVDid:CNNVD-202002-746
db:NVDid:CVE-2020-1813

LAST UPDATE DATE

2024-11-23T22:58:12.680000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2020-006725date:2020-07-15T00:00:00
db:CNNVDid:CNNVD-202002-746date:2021-08-16T00:00:00
db:NVDid:CVE-2020-1813date:2024-11-21T05:11:25.837

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2020-006725date:2020-07-15T00:00:00
db:CNNVDid:CNNVD-202002-746date:2020-02-12T00:00:00
db:NVDid:CVE-2020-1813date:2020-06-15T15:15:09.583