CVE-2020-9081
MEDIUM WAF: Low
CVSS 6.8
Published: 2024-12-27
CWE-863
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081.
WAF Coverage Analysis
Incorrect Authorization
Low WAF Coverage
OWASP: A01:2021 Broken Access Control
Affected Software
| Vendor | Product | Version |
|---|---|---|
| huawei | mate_20_firmware | up to 10.1.0.160\(c00e160r3p8\) |
| huawei | p30_firmware | up to 10.1.0.160\(c00e160r2p11\) |
| huawei | p30_pro_firmware | up to 10.1.0.160\(c00e160r2p8\) |
| huawei | princeton-al10d_firmware | up to 10.1.0.160\(c00e160r2p11\) |
| huawei | yale-al00a_firmware | up to 10.1.0.160\(c00e160r8p12\) |
| huawei | yale-al50a_firmware | up to 10.1.0.88\(c00e88r8p1\) |
| huawei | yalep-al10b_firmware | up to 10.1.0.160\(c00e160r8p12\) |
| huawei | mate_20_firmware | up to 10.1.0.160\(c01e160r2p8\) |
| huawei | p30_pro_firmware | up to 10.1.0.160\(c01e160r2p8\) |
References
- www.huawei.com (Vendor Advisory)