ID

VAR-202101-1001


CVE

CVE-2020-9141


TITLE

plural  Huawei  Insufficient verification vulnerability in data reliability on smartphones

Trust: 0.8

sources: JVNDB: JVNDB-2020-015407

DESCRIPTION

There is a improper privilege management vulnerability in some Huawei smartphone. Successful exploitation of this vulnerability can cause information disclosure and malfunctions due to insufficient verification of data authenticity. Huawei Emui is an Android-based mobile operating system developed by Huawei in China. Honor Magic Ui is an Android-based mobile operating system developed by China Honor Company

Trust: 1.71

sources: NVD: CVE-2020-9141 // JVNDB: JVNDB-2020-015407 // VULHUB: VHN-187266

AFFECTED PRODUCTS

vendor:huaweimodel:emuiscope:eqversion:10.1.1

Trust: 1.0

vendor:huaweimodel:magic uiscope:eqversion:3.1.1

Trust: 1.0

vendor:huaweimodel:magic uiscope:eqversion:3.1.0

Trust: 1.0

vendor:huaweimodel:emuiscope:eqversion:10.1.0

Trust: 1.0

vendor:huaweimodel:emuiscope: - version: -

Trust: 0.8

vendor:huaweimodel:magic uiscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-015407 // NVD: CVE-2020-9141

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-9141
value: CRITICAL

Trust: 1.0

NVD: CVE-2020-9141
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202101-1100
value: CRITICAL

Trust: 0.6

VULHUB: VHN-187266
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-9141
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-187266
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-9141
baseSeverity: CRITICAL
baseScore: 9.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 5.2
version: 3.1

Trust: 1.0

NVD: CVE-2020-9141
baseSeverity: CRITICAL
baseScore: 9.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-187266 // JVNDB: JVNDB-2020-015407 // CNNVD: CNNVD-202101-1100 // NVD: CVE-2020-9141

PROBLEMTYPE DATA

problemtype:CWE-269

Trust: 1.1

problemtype:CWE-345

Trust: 1.1

problemtype:Improper authority management (CWE-269) [NVD Evaluation ]

Trust: 0.8

problemtype: Inadequate verification of data reliability (CWE-345) [NVD Evaluation ]

Trust: 0.8

sources: VULHUB: VHN-187266 // JVNDB: JVNDB-2020-015407 // NVD: CVE-2020-9141

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202101-1100

TYPE

data forgery

Trust: 0.6

sources: CNNVD: CNNVD-202101-1100

PATCH

title:Huawei EMUI/Magic UI security updates Dec-20url:https://consumer.huawei.com/en/support/bulletin/2020/12/

Trust: 0.8

title:Repair measures for Huawei smartphone authorization bugsurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=139460

Trust: 0.6

sources: JVNDB: JVNDB-2020-015407 // CNNVD: CNNVD-202101-1100

EXTERNAL IDS

db:NVDid:CVE-2020-9141

Trust: 2.5

db:JVNDBid:JVNDB-2020-015407

Trust: 0.8

db:CNNVDid:CNNVD-202101-1100

Trust: 0.7

db:VULHUBid:VHN-187266

Trust: 0.1

sources: VULHUB: VHN-187266 // JVNDB: JVNDB-2020-015407 // CNNVD: CNNVD-202101-1100 // NVD: CVE-2020-9141

REFERENCES

url:https://consumer.huawei.com/en/support/bulletin/2020/12/

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-9141

Trust: 1.4

sources: VULHUB: VHN-187266 // JVNDB: JVNDB-2020-015407 // CNNVD: CNNVD-202101-1100 // NVD: CVE-2020-9141

SOURCES

db:VULHUBid:VHN-187266
db:JVNDBid:JVNDB-2020-015407
db:CNNVDid:CNNVD-202101-1100
db:NVDid:CVE-2020-9141

LAST UPDATE DATE

2024-08-14T15:33:17.230000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-187266date:2021-07-21T00:00:00
db:JVNDBid:JVNDB-2020-015407date:2021-09-21T09:03:00
db:CNNVDid:CNNVD-202101-1100date:2021-01-21T00:00:00
db:NVDid:CVE-2020-9141date:2021-07-21T11:39:23.747

SOURCES RELEASE DATE

db:VULHUBid:VHN-187266date:2021-01-13T00:00:00
db:JVNDBid:JVNDB-2020-015407date:2021-09-21T00:00:00
db:CNNVDid:CNNVD-202101-1100date:2021-01-13T00:00:00
db:NVDid:CVE-2020-9141date:2021-01-13T22:15:14.083