CVE-2020-9235

MEDIUM

Huawei Smartphones - Information Disclosure via Input Validation Error

Title source: llm
STIX 2.1

Description

Huawei smartphones HONOR 20 PRO Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C185E3R5P1),Versions earlier than 10.1.0.231(C636E3R3P1);Versions earlier than 10.1.0.212(C432E10R3P4),Versions earlier than 10.1.0.213(C636E3R4P3),Versions earlier than 10.1.0.214(C10E5R4P3),Versions earlier than 10.1.0.214(C185E3R3P3);Versions earlier than 10.1.0.212(C00E210R5P1);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C01E160R2P11);Versions earlier than 10.1.0.160(C00E160R2P11);Versions earlier than 10.1.0.160(C00E160R8P12);Versions earlier than 10.1.0.230(C432E9R5P1),Versions earlier than 10.1.0.231(C10E3R3P2),Versions earlier than 10.1.0.231(C636E3R3P1);Versions earlier than 10.1.0.225(C431E3R1P2),Versions earlier than 10.1.0.225(C432E3R1P2) contain an information vulnerability. A module has a design error that is lack of control of input. Attackers can exploit this vulnerability to obtain some information. This can lead to information leak.

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 9.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-20
Status published
Products (10)
huawei/honor_20_pro_firmware < 10.1.0.230\(c432e9r5p1\)
huawei/honor_view_20_firmware < 10.1.0.212\(c432e10r3p4\)
huawei/oxfords-an00a_firmware < 10.1.0.212\(c00e210r5p1\)
huawei/princeton-al10b_firmware < 10.1.0.160\(c00e160r2p11\)
huawei/princeton-al10d_firmware < 10.1.0.160\(c00e160r2p11\)
huawei/princeton-tl10c_firmware < 10.1.0.160\(c01e160r2p11\)
huawei/tony-al00b_firmware < 10.1.0.160\(c00e160r2p11\)
huawei/yale-al00a_firmware < 10.1.0.160\(c00e160r8p12\)
huawei/yale-l21a_firmware < 10.1.0.230\(c432e9r5p1\)
huawei/yale-l61a_firmware < 10.1.0.225\(c431e3r1p2\)
Published Sep 03, 2020
Tracked Since Feb 18, 2026