CVE-2020-9081

Jan. 10, 2025, 8:37 p.m.

3.5
Low

Description

There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081.

Product(s) Impacted

Vendor Product Versions
Huawei
  • Mate 20 Firmware
  • Mate 20
  • P30 Firmware
  • P30
  • P30 Pro Firmware
  • P30 Pro
  • Princeton-al10d Firmware
  • Princeton-al10d
  • Yale-al00a Firmware
  • Yale-al00a
  • Yale-al50a Firmware
  • Yale-al50a
  • Yalep-al10b Firmware
  • Yalep-al10b
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -
  • *
  • -

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-285
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-863
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
o huawei mate_20_firmware / / / / / / / /
h huawei mate_20 - / / / / / / /
o huawei p30_firmware / / / / / / / /
h huawei p30 - / / / / / / /
o huawei p30_pro_firmware / / / / / / / /
h huawei p30_pro - / / / / / / /
o huawei princeton-al10d_firmware / / / / / / / /
h huawei princeton-al10d - / / / / / / /
o huawei yale-al00a_firmware / / / / / / / /
h huawei yale-al00a - / / / / / / /
o huawei yale-al50a_firmware / / / / / / / /
h huawei yale-al50a - / / / / / / /
o huawei yalep-al10b_firmware / / / / / / / /
h huawei yalep-al10b - / / / / / / /
o huawei mate_20_firmware / / / / / / / /
h huawei mate_20 - / / / / / / /
o huawei p30_pro_firmware / / / / / / / /
h huawei p30_pro - / / / / / / /

CVSS Score

3.5 / 10

CVSS Data - 3.1

  • Attack Vector: PHYSICAL
  • Attack Complexity: LOW
  • Privileges Required: NONE
  • Scope: UNCHANGED
  • Confidentiality Impact: LOW
  • Integrity Impact: LOW
  • Availability Impact: NONE
  • CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

    View Vector String

Timeline

Published: Dec. 27, 2024, 10:15 a.m.
Last Modified: Jan. 10, 2025, 8:37 p.m.

Status : Analyzed

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

psirt@huawei.com

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.