ID

VAR-202006-1058


CVE

CVE-2020-1834


TITLE

HUAWEI P30 and P30 Pro Vulnerability in data integrity verification deficiency in

Trust: 0.8

sources: JVNDB: JVNDB-2020-006750

DESCRIPTION

HUAWEI P30 and HUAWEI P30 Pro with versions earlier than 10.1.0.135(C00E135R2P11) and versions earlier than 10.1.0.135(C00E135R2P8) have an insufficient integrity check vulnerability. The system does not check certain software package's integrity sufficiently. Successful exploit could allow an attacker to load a crafted software package to the device. Both Huawei P30 and Huawei P30 Pro are smartphones of China's Huawei (Huawei) company

Trust: 2.16

sources: NVD: CVE-2020-1834 // JVNDB: JVNDB-2020-006750 // CNVD: CNVD-2020-52416

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-52416

AFFECTED PRODUCTS

vendor:huaweimodel:p30scope:ltversion:10.1.0.135\(c00e135r2p11\)

Trust: 1.0

vendor:huaweimodel:p30 proscope:ltversion:10.1.0.135\(c00e135r2p8\)

Trust: 1.0

vendor:huaweimodel:mate 30 proscope:eqversion:10.1.0.135(c00e135r2p8)

Trust: 0.8

vendor:huaweimodel:mate 30scope:eqversion:10.1.0.135(c00e135r2p11)

Trust: 0.8

vendor:huaweimodel:p30 <10.1.0.135scope: - version: -

Trust: 0.6

vendor:huaweimodel:p30 pro <10.1.0.135scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-52416 // JVNDB: JVNDB-2020-006750 // NVD: CVE-2020-1834

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-1834
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-006750
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2020-52416
value: LOW

Trust: 0.6

CNNVD: CNNVD-202006-1198
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-1834
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-006750
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-52416
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-1834
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 0.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-006750
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-52416 // JVNDB: JVNDB-2020-006750 // CNNVD: CNNVD-202006-1198 // NVD: CVE-2020-1834

PROBLEMTYPE DATA

problemtype:CWE-354

Trust: 1.8

sources: JVNDB: JVNDB-2020-006750 // NVD: CVE-2020-1834

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202006-1198

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-006750

PATCH

title:huawei-sa-20200617-01-smartphone url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200617-01-smartphone-en

Trust: 0.8

title:Patch for Huawei P30 and P30 Pro insufficient integrity check vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/234445

Trust: 0.6

title:Huawei P30 and P30 Pro Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=121887

Trust: 0.6

sources: CNVD: CNVD-2020-52416 // JVNDB: JVNDB-2020-006750 // CNNVD: CNNVD-202006-1198

EXTERNAL IDS

db:NVDid:CVE-2020-1834

Trust: 3.0

db:JVNDBid:JVNDB-2020-006750

Trust: 0.8

db:CNVDid:CNVD-2020-52416

Trust: 0.6

db:CNNVDid:CNNVD-202006-1198

Trust: 0.6

sources: CNVD: CNVD-2020-52416 // JVNDB: JVNDB-2020-006750 // CNNVD: CNNVD-202006-1198 // NVD: CVE-2020-1834

REFERENCES

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200617-01-smartphone-en

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-1834

Trust: 1.4

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20200617-01-smartphone-cn

Trust: 1.2

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-1834

Trust: 0.8

sources: CNVD: CNVD-2020-52416 // JVNDB: JVNDB-2020-006750 // CNNVD: CNNVD-202006-1198 // NVD: CVE-2020-1834

SOURCES

db:CNVDid:CNVD-2020-52416
db:JVNDBid:JVNDB-2020-006750
db:CNNVDid:CNNVD-202006-1198
db:NVDid:CVE-2020-1834

LAST UPDATE DATE

2024-11-23T22:58:12.580000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-52416date:2020-09-17T00:00:00
db:JVNDBid:JVNDB-2020-006750date:2020-07-16T00:00:00
db:CNNVDid:CNNVD-202006-1198date:2020-08-27T00:00:00
db:NVDid:CVE-2020-1834date:2024-11-21T05:11:27.567

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-52416date:2020-09-17T00:00:00
db:JVNDBid:JVNDB-2020-006750date:2020-07-16T00:00:00
db:CNNVDid:CNNVD-202006-1198date:2020-06-17T00:00:00
db:NVDid:CVE-2020-1834date:2020-06-18T14:15:11.187