3.3
CVE-2020-9089
- EPSS 0.02%
- Veröffentlicht 27.12.2024 10:15:13
- Zuletzt bearbeitet 13.01.2025 18:58:56
- Quelle psirt@huawei.com
- Teams Watchlist Login
- Unerledigt Login
There is an information vulnerability in Huawei smartphones. A function in a module can be called without verifying the caller's access. Attackers with user access can exploit this vulnerability to obtain some information. This can lead to information leak. (Vulnerability ID: HWPSIRT-2019-12141) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9089.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ P30 Pro Firmware Version < 10.1.0.120\(c431e19r2p5\)
Huawei ≫ P30 Pro Firmware Version < 10.1.0.120\(c432e19r2p5\)
Huawei ≫ P30 Pro Firmware Version < 10.1.0.126\(c10e11r5p1\)
Huawei ≫ P30 Pro Firmware Version < 10.1.0.126\(c461e11r3p1\)
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.037 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
psirt@huawei.com | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.