CVE-2020-9081
27.12.2024, 10:15
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081.Enginsight
Vendor | Product | Version |
---|---|---|
huawei | mate_20_firmware | 𝑥 < 10.1.0.160\(c00e160r3p8\) |
huawei | p30_firmware | 𝑥 < 10.1.0.160\(c00e160r2p11\) |
huawei | p30_pro_firmware | 𝑥 < 10.1.0.160\(c00e160r2p8\) |
huawei | princeton-al10d_firmware | 𝑥 < 10.1.0.160\(c00e160r2p11\) |
huawei | yale-al00a_firmware | 𝑥 < 10.1.0.160\(c00e160r8p12\) |
huawei | yale-al50a_firmware | 𝑥 < 10.1.0.88\(c00e88r8p1\) |
huawei | yalep-al10b_firmware | 𝑥 < 10.1.0.160\(c00e160r8p12\) |
huawei | mate_20_firmware | 𝑥 < 10.1.0.160\(c01e160r2p8\) |
huawei | p30_pro_firmware | 𝑥 < 10.1.0.160\(c01e160r2p8\) |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-285 - Improper AuthorizationThe software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
- CWE-863 - Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.