CVE-2020-1792
MEDIUMHonor V10 <BKL-AL20 10.0.0.156(C00E156R2P4) & <BKL-L09 10.0.0.146(C...
Title source: llmDescription
Honor V10 smartphones with versions earlier than BKL-AL20 10.0.0.156(C00E156R2P4) and versions earlier than BKL-L09 10.0.0.146(C432E4R1P4) have an out of bounds write vulnerability. The software writes data past the end of the intended buffer because of insufficient validation of certain parameter when initializing certain driver program. An attacker could trick the user into installing a malicious application, successful exploit could cause the device to reboot.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200226-01-smartphone-en
Scores
CVSS v3
5.5
EPSS
0.0014
EPSS Percentile
33.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-787
Status
published
Products (1)
huawei/honor_v10_firmware
< bkl-al20_10.0.0.156\(c00e156r2p4\)
Published
Feb 28, 2020
Tracked Since
Feb 18, 2026