CVE-2020-9107

MEDIUM

Huawei P30 Pro Firmware - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have an out-of-bounds read and write vulnerability. An unauthenticated attacker crafts malformed message with specific parameter and sends the message to the affected products. Due to insufficient validation of message, which may be exploited to cause the process reboot.

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0017
EPSS Percentile 37.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-125 CWE-787
Status published
Products (1)
huawei/p30_pro_firmware < 10.1.0.160\(c00e160r2p8\)
Published Oct 12, 2020
Tracked Since Feb 18, 2026