CVE-2020-9081

There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144)



This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.5 LOW
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
huaweiCNA
3.5 LOW
PHYSICAL
LOW
NONE
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
VendorProductVersion
huaweimate_20_firmware
𝑥
< 10.1.0.160\(c00e160r3p8\)
huaweip30_firmware
𝑥
< 10.1.0.160\(c00e160r2p11\)
huaweip30_pro_firmware
𝑥
< 10.1.0.160\(c00e160r2p8\)
huaweiprinceton-al10d_firmware
𝑥
< 10.1.0.160\(c00e160r2p11\)
huaweiyale-al00a_firmware
𝑥
< 10.1.0.160\(c00e160r8p12\)
huaweiyale-al50a_firmware
𝑥
< 10.1.0.88\(c00e88r8p1\)
huaweiyalep-al10b_firmware
𝑥
< 10.1.0.160\(c00e160r8p12\)
huaweimate_20_firmware
𝑥
< 10.1.0.160\(c01e160r2p8\)
huaweip30_pro_firmware
𝑥
< 10.1.0.160\(c01e160r2p8\)
𝑥
= Vulnerable software versions