ID

VAR-202007-0976


CVE

CVE-2020-1836


TITLE

Huawei P30 and P30 Pro information disclosure vulnerability

Trust: 1.2

sources: CNVD: CNVD-2020-51528 // CNNVD: CNNVD-202007-274

DESCRIPTION

HUAWEI P30 with versions earlier than 10.1.0.160(C00E160R2P11) and HUAWEI P30 Pro with versions earlier than 10.1.0.160(C00E160R2P8) have an information disclosure vulnerability. Certain function's default configuration in the system seems insecure, an attacker should craft a WI-FI hotspot to launch the attack. Successful exploit could cause information disclosure. Attackers can use this vulnerability to obtain information by forging a WI-FI hotspot

Trust: 2.16

sources: NVD: CVE-2020-1836 // JVNDB: JVNDB-2020-007480 // CNVD: CNVD-2020-51528

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-51528

AFFECTED PRODUCTS

vendor:huaweimodel:p30 proscope:ltversion:10.1.0.160\(c00e160r2p8\)

Trust: 1.0

vendor:huaweimodel:p30scope:ltversion:10.1.0.160\(c00e160r2p11\)

Trust: 1.0

vendor:huaweimodel:p30 proscope:eqversion:10.1.0.160(c00e160r2p8)

Trust: 0.8

vendor:huaweimodel:p30scope:eqversion:10.1.0.160(c00e160r2p11)

Trust: 0.8

vendor:huaweimodel:p30 <10.1.0.160scope: - version: -

Trust: 0.6

vendor:huaweimodel:p30 pro <10.1.0.160scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-51528 // JVNDB: JVNDB-2020-007480 // NVD: CVE-2020-1836

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-1836
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-007480
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2020-51528
value: LOW

Trust: 0.6

CNNVD: CNNVD-202007-274
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-1836
severity: LOW
baseScore: 2.9
vectorString: AV:A/AC:M/AU:N/C:P/I:N/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 5.5
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-007480
severity: LOW
baseScore: 2.9
vectorString: AV:A/AC:M/AU:N/C:P/I:N/A:N
accessVector: ADJACENT NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-51528
severity: LOW
baseScore: 2.9
vectorString: AV:A/AC:M/AU:N/C:P/I:N/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 5.5
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-1836
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: ADJACENT
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.6
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-007480
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: ADJACENT NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-51528 // JVNDB: JVNDB-2020-007480 // CNNVD: CNNVD-202007-274 // NVD: CVE-2020-1836

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-200

Trust: 0.8

sources: JVNDB: JVNDB-2020-007480 // NVD: CVE-2020-1836

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-202007-274

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-202007-274

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-007480

PATCH

title:huawei-sa-20200624-01-smartphoneurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200624-01-smartphone-en

Trust: 0.8

title:Patch for Huawei P30 and P30 Pro information disclosure vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/233299

Trust: 0.6

title:Huawei P30 and P30 Pro Repair measures for information disclosure vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=123514

Trust: 0.6

sources: CNVD: CNVD-2020-51528 // JVNDB: JVNDB-2020-007480 // CNNVD: CNNVD-202007-274

EXTERNAL IDS

db:NVDid:CVE-2020-1836

Trust: 3.0

db:NSFOCUSid:47099

Trust: 1.2

db:JVNDBid:JVNDB-2020-007480

Trust: 0.8

db:CNVDid:CNVD-2020-51528

Trust: 0.6

db:CNNVDid:CNNVD-202007-274

Trust: 0.6

sources: CNVD: CNVD-2020-51528 // JVNDB: JVNDB-2020-007480 // CNNVD: CNNVD-202007-274 // NVD: CVE-2020-1836

REFERENCES

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200624-01-smartphone-en

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2020-1836

Trust: 1.4

url:http://www.nsfocus.net/vulndb/47099

Trust: 1.2

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-1836

Trust: 0.8

sources: CNVD: CNVD-2020-51528 // JVNDB: JVNDB-2020-007480 // CNNVD: CNNVD-202007-274 // NVD: CVE-2020-1836

SOURCES

db:CNVDid:CNVD-2020-51528
db:JVNDBid:JVNDB-2020-007480
db:CNNVDid:CNNVD-202007-274
db:NVDid:CVE-2020-1836

LAST UPDATE DATE

2024-11-23T22:21:04.828000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-51528date:2020-09-11T00:00:00
db:JVNDBid:JVNDB-2020-007480date:2020-08-14T00:00:00
db:CNNVDid:CNNVD-202007-274date:2022-03-15T00:00:00
db:NVDid:CVE-2020-1836date:2024-11-21T05:11:27.817

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-51528date:2020-09-09T00:00:00
db:JVNDBid:JVNDB-2020-007480date:2020-08-14T00:00:00
db:CNNVDid:CNNVD-202007-274date:2020-07-06T00:00:00
db:NVDid:CVE-2020-1836date:2020-07-06T19:15:12.400