ID

VAR-202007-1263


CVE

CVE-2020-9251


TITLE

HUAWEI Mate 20 Authentication vulnerabilities in smartphones

Trust: 0.8

sources: JVNDB: JVNDB-2020-008711

DESCRIPTION

HUAWEI Mate 20 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have an improper authorization vulnerability. The software does not properly restrict certain operation in certain scenario, the attacker should do certain configuration before the user turns on student mode function. Successful exploit could allow the attacker to bypass the limit of student mode function. Affected product versions include: HUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8). HUAWEI Mate 20 There is an authentication vulnerability in smartphones.Information may be tampered with. Huawei Mate 20 is a smartphone launched by Huawei

Trust: 2.25

sources: NVD: CVE-2020-9251 // JVNDB: JVNDB-2020-008711 // CNVD: CNVD-2020-46469 // VULMON: CVE-2020-9251

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-46469

AFFECTED PRODUCTS

vendor:huaweimodel:p30scope:ltversion:10.1.0.160\(c00e160r3p8\)

Trust: 1.0

vendor:huaweimodel:p30scope:eqversion:10.1.0.160(c00e160r2p11)

Trust: 0.8

vendor:huaweimodel:mate <10.1.0.160scope:eqversion:20

Trust: 0.6

sources: CNVD: CNVD-2020-46469 // JVNDB: JVNDB-2020-008711 // NVD: CVE-2020-9251

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-9251
value: LOW

Trust: 1.0

NVD: JVNDB-2020-008711
value: LOW

Trust: 0.8

CNVD: CNVD-2020-46469
value: LOW

Trust: 0.6

CNNVD: CNNVD-202007-1381
value: LOW

Trust: 0.6

VULMON: CVE-2020-9251
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2020-9251
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: JVNDB-2020-008711
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-46469
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-9251
baseSeverity: LOW
baseScore: 2.4
vectorString: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 0.9
impactScore: 1.4
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-008711
baseSeverity: LOW
baseScore: 2.4
vectorString: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-46469 // VULMON: CVE-2020-9251 // JVNDB: JVNDB-2020-008711 // CNNVD: CNNVD-202007-1381 // NVD: CVE-2020-9251

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-287

Trust: 0.8

sources: JVNDB: JVNDB-2020-008711 // NVD: CVE-2020-9251

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202007-1381

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-008711

PATCH

title:huawei-sa-20200722-02-smartphoneurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200722-02-smartphone-en

Trust: 0.8

title:Patch for Huawei Mate 20 improper authorization vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/230836

Trust: 0.6

title:Huawei Mate 20 Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=125178

Trust: 0.6

sources: CNVD: CNVD-2020-46469 // JVNDB: JVNDB-2020-008711 // CNNVD: CNNVD-202007-1381

EXTERNAL IDS

db:NVDid:CVE-2020-9251

Trust: 3.1

db:JVNDBid:JVNDB-2020-008711

Trust: 0.8

db:CNVDid:CNVD-2020-46469

Trust: 0.6

db:NSFOCUSid:47941

Trust: 0.6

db:CNNVDid:CNNVD-202007-1381

Trust: 0.6

db:VULMONid:CVE-2020-9251

Trust: 0.1

sources: CNVD: CNVD-2020-46469 // VULMON: CVE-2020-9251 // JVNDB: JVNDB-2020-008711 // CNNVD: CNNVD-202007-1381 // NVD: CVE-2020-9251

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2020-9251

Trust: 2.0

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200722-02-smartphone-en

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-9251

Trust: 0.8

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20200722-02-smartphone-cn

Trust: 0.6

url:http://www.nsfocus.net/vulndb/47941

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2020-46469 // VULMON: CVE-2020-9251 // JVNDB: JVNDB-2020-008711 // CNNVD: CNNVD-202007-1381 // NVD: CVE-2020-9251

CREDITS

Ding Yicong

Trust: 0.6

sources: CNNVD: CNNVD-202007-1381

SOURCES

db:CNVDid:CNVD-2020-46469
db:VULMONid:CVE-2020-9251
db:JVNDBid:JVNDB-2020-008711
db:CNNVDid:CNNVD-202007-1381
db:NVDid:CVE-2020-9251

LAST UPDATE DATE

2024-11-23T22:58:11.029000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-46469date:2020-08-17T00:00:00
db:VULMONid:CVE-2020-9251date:2021-07-21T00:00:00
db:JVNDBid:JVNDB-2020-008711date:2020-09-18T00:00:00
db:CNNVDid:CNNVD-202007-1381date:2020-08-20T00:00:00
db:NVDid:CVE-2020-9251date:2024-11-21T05:40:16.453

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-46469date:2020-08-17T00:00:00
db:VULMONid:CVE-2020-9251date:2020-07-27T00:00:00
db:JVNDBid:JVNDB-2020-008711date:2020-09-18T00:00:00
db:CNNVDid:CNNVD-202007-1381date:2020-07-22T00:00:00
db:NVDid:CVE-2020-9251date:2020-07-27T13:15:12.917