ID

VAR-202007-1274


CVE

CVE-2020-9226


TITLE

HUAWEI P30 Digital Signature Verification Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2020-007479

DESCRIPTION

HUAWEI P30 with versions earlier than 10.1.0.135(C00E135R2P11) have an improper signature verification vulnerability. The system does not improper check signature of specific software package, an attacker may exploit this vulnerability to load a crafted software package to the device. Huawei P30 is a smart phone of China's Huawei (Huawei) company. There is a security vulnerability in Huawei P30 10.1.0.135 (C00E135R2P11)

Trust: 2.25

sources: NVD: CVE-2020-9226 // JVNDB: JVNDB-2020-007479 // CNVD: CNVD-2020-52414 // VULMON: CVE-2020-9226

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-52414

AFFECTED PRODUCTS

vendor:huaweimodel:p30scope:ltversion:10.1.0.135\(c00e135r2p11\)

Trust: 1.0

vendor:huaweimodel:p30scope:eqversion:10.1.0.135(c00e135r2p11)

Trust: 0.8

vendor:huaweimodel:p30 <10.1.0.135scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2020-52414 // JVNDB: JVNDB-2020-007479 // NVD: CVE-2020-9226

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-9226
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-007479
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2020-52414
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202007-101
value: MEDIUM

Trust: 0.6

VULMON: CVE-2020-9226
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-9226
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: JVNDB-2020-007479
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-52414
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-9226
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-007479
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2020-52414 // VULMON: CVE-2020-9226 // JVNDB: JVNDB-2020-007479 // CNNVD: CNNVD-202007-101 // NVD: CVE-2020-9226

PROBLEMTYPE DATA

problemtype:CWE-347

Trust: 1.8

sources: JVNDB: JVNDB-2020-007479 // NVD: CVE-2020-9226

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202007-101

TYPE

data forgery

Trust: 0.6

sources: CNNVD: CNNVD-202007-101

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-007479

PATCH

title:huawei-sa-20200701-02-smartphoneurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200701-02-smartphone-en

Trust: 0.8

title:Patch for Huawei P30 data forgery issue vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/233965

Trust: 0.6

title:Huawei P30 Repair measures for data forgery problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=123469

Trust: 0.6

sources: CNVD: CNVD-2020-52414 // JVNDB: JVNDB-2020-007479 // CNNVD: CNNVD-202007-101

EXTERNAL IDS

db:NVDid:CVE-2020-9226

Trust: 3.1

db:NSFOCUSid:47056

Trust: 1.2

db:JVNDBid:JVNDB-2020-007479

Trust: 0.8

db:CNVDid:CNVD-2020-52414

Trust: 0.6

db:CNNVDid:CNNVD-202007-101

Trust: 0.6

db:VULMONid:CVE-2020-9226

Trust: 0.1

sources: CNVD: CNVD-2020-52414 // VULMON: CVE-2020-9226 // JVNDB: JVNDB-2020-007479 // CNNVD: CNNVD-202007-101 // NVD: CVE-2020-9226

REFERENCES

url:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200701-02-smartphone-en

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-9226

Trust: 1.4

url:http://www.nsfocus.net/vulndb/47056

Trust: 1.2

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-9226

Trust: 0.8

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20200701-02-smartphone-cn

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/347.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2020-52414 // VULMON: CVE-2020-9226 // JVNDB: JVNDB-2020-007479 // CNNVD: CNNVD-202007-101 // NVD: CVE-2020-9226

SOURCES

db:CNVDid:CNVD-2020-52414
db:VULMONid:CVE-2020-9226
db:JVNDBid:JVNDB-2020-007479
db:CNNVDid:CNNVD-202007-101
db:NVDid:CVE-2020-9226

LAST UPDATE DATE

2024-11-23T22:33:24.064000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-52414date:2020-09-17T00:00:00
db:VULMONid:CVE-2020-9226date:2020-07-09T00:00:00
db:JVNDBid:JVNDB-2020-007479date:2020-08-14T00:00:00
db:CNNVDid:CNNVD-202007-101date:2020-07-10T00:00:00
db:NVDid:CVE-2020-9226date:2024-11-21T05:40:11.470

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-52414date:2020-09-15T00:00:00
db:VULMONid:CVE-2020-9226date:2020-07-06T00:00:00
db:JVNDBid:JVNDB-2020-007479date:2020-08-14T00:00:00
db:CNNVDid:CNNVD-202007-101date:2020-07-01T00:00:00
db:NVDid:CVE-2020-9226date:2020-07-06T19:15:12.713