ID

VAR-202007-0978


CVE

CVE-2020-1838


TITLE

HUAWEI Mate 30 Pro Authentication vulnerabilities in

Trust: 0.8

sources: JVNDB: JVNDB-2020-007481

DESCRIPTION

HUAWEI Mate 30 Pro with versions earlier than 10.1.0.150(C00E136R5P3) have is an improper authentication vulnerability. The device does not sufficiently validate certain credential of user's face, an attacker could craft the credential of the user, successful exploit could allow the attacker to pass the authentication with the crafted credential. The vulnerability is caused by the device not fully verifying the user's facial credentials

Trust: 2.16

sources: NVD: CVE-2020-1838 // JVNDB: JVNDB-2020-007481 // CNVD: CNVD-2020-51533

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-51533

AFFECTED PRODUCTS

vendor:huaweimodel:mate 30 proscope:ltversion:10.1.0.150\(c00e136r5p3\)

Trust: 1.0

vendor:huaweimodel:mate 30 proscope:eqversion:10.1.0.150(c00e136r5p3)

Trust: 0.8

vendor:huaweimodel:mate pro <10.1.0.150scope:eqversion:30

Trust: 0.6

sources: CNVD: CNVD-2020-51533 // JVNDB: JVNDB-2020-007481 // NVD: CVE-2020-1838

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-1838
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-007481
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2020-51533
value: LOW

Trust: 0.6

CNNVD: CNNVD-202007-077
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2020-1838
severity: LOW
baseScore: 1.9
vectorString: AV:L/AC:M/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: JVNDB-2020-007481
severity: LOW
baseScore: 1.9
vectorString: AV:L/AC:M/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-51533
severity: LOW
baseScore: 1.9
vectorString: AV:L/AC:M/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-1838
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-007481
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-51533 // JVNDB: JVNDB-2020-007481 // CNNVD: CNNVD-202007-077 // NVD: CVE-2020-1838

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.8

sources: JVNDB: JVNDB-2020-007481 // NVD: CVE-2020-1838

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202007-077

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202007-077

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-007481

PATCH

title:huawei-sa-20200701-03-smartphoneurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200701-03-smartphone-en

Trust: 0.8

title:Patch for Huawei Mate 30 Pro authorization issue vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/233314

Trust: 0.6

title:Huawei Mate 30 Pro Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=123465

Trust: 0.6

sources: CNVD: CNVD-2020-51533 // JVNDB: JVNDB-2020-007481 // CNNVD: CNNVD-202007-077

EXTERNAL IDS

db:NVDid:CVE-2020-1838

Trust: 3.0

db:JVNDBid:JVNDB-2020-007481

Trust: 0.8

db:CNVDid:CNVD-2020-51533

Trust: 0.6

db:NSFOCUSid:47073

Trust: 0.6

db:CNNVDid:CNNVD-202007-077

Trust: 0.6

sources: CNVD: CNVD-2020-51533 // JVNDB: JVNDB-2020-007481 // CNNVD: CNNVD-202007-077 // NVD: CVE-2020-1838

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2020-1838

Trust: 2.0

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200701-03-smartphone-en

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-1838

Trust: 0.8

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20200701-03-smartphone-cn

Trust: 0.6

url:http://www.nsfocus.net/vulndb/47073

Trust: 0.6

sources: CNVD: CNVD-2020-51533 // JVNDB: JVNDB-2020-007481 // CNNVD: CNNVD-202007-077 // NVD: CVE-2020-1838

SOURCES

db:CNVDid:CNVD-2020-51533
db:JVNDBid:JVNDB-2020-007481
db:CNNVDid:CNNVD-202007-077
db:NVDid:CVE-2020-1838

LAST UPDATE DATE

2024-11-23T22:44:28.782000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-51533date:2020-09-11T00:00:00
db:JVNDBid:JVNDB-2020-007481date:2020-08-14T00:00:00
db:CNNVDid:CNNVD-202007-077date:2020-07-10T00:00:00
db:NVDid:CVE-2020-1838date:2024-11-21T05:11:28.070

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-51533date:2020-09-09T00:00:00
db:JVNDBid:JVNDB-2020-007481date:2020-08-14T00:00:00
db:CNNVDid:CNNVD-202007-077date:2020-07-01T00:00:00
db:NVDid:CVE-2020-1838date:2020-07-06T19:15:12.463