7.8

CVE-2020-9254

HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a logic check error vulnerability. A logic error occurs when the software checking the size of certain parameter, the attacker should trick the user into installing a malicious application, successful exploit may cause code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei ≫ P30 Pro Firmware Version < 10.1.0.123\(c432e19r2p5patch02\)
   Huawei ≫ P30 Pro Version -
Huawei ≫ P30 Pro Firmware Version < 10.1.0.126\(c10e11r5p1\)
   Huawei ≫ P30 Pro Version -
Huawei ≫ P30 Pro Firmware Version < 10.1.0.160\(c00e160r2p8\)
   Huawei ≫ P30 Pro Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.88% 0.543
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200715-04-smartphone-en
Vendor Advisory