CVE-2020-9081

MEDIUM WAF: Low
CVSS 6.8 Published: 2024-12-27
CWE-863

There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081.

WAF Coverage Analysis

Incorrect Authorization Low WAF Coverage

OWASP: A01:2021 Broken Access Control

Affected Software

VendorProductVersion
huaweimate_20_firmwareup to 10.1.0.160\(c00e160r3p8\)
huaweip30_firmwareup to 10.1.0.160\(c00e160r2p11\)
huaweip30_pro_firmwareup to 10.1.0.160\(c00e160r2p8\)
huaweiprinceton-al10d_firmwareup to 10.1.0.160\(c00e160r2p11\)
huaweiyale-al00a_firmwareup to 10.1.0.160\(c00e160r8p12\)
huaweiyale-al50a_firmwareup to 10.1.0.88\(c00e88r8p1\)
huaweiyalep-al10b_firmwareup to 10.1.0.160\(c00e160r8p12\)
huaweimate_20_firmwareup to 10.1.0.160\(c01e160r2p8\)
huaweip30_pro_firmwareup to 10.1.0.160\(c01e160r2p8\)

References

Back to CVE Database