CVE-2020-9247

HIGH

Huawei Honor 20 Pro Firmware - Buffer Overflow

Title source: rule

Description

There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code execution. Affected product include Huawei HONOR 20 PRO, Mate 20, Mate 20 Pro, Mate 20 X, P30, P30 Pro, Hima-L29C, Laya-AL00EP, Princeton-AL10B, Tony-AL00B, Yale-L61A, Yale-TL00B and YaleP-AL10B.

Scores

CVSS v3 7.8
EPSS 0.0035
EPSS Percentile 57.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (14)
huawei/hima-l29c_firmware < 10.1.0.273\(c185e5r2p4\)
huawei/honor_20_pro_firmware < 10.1.0.230\(c432e9r5p1\)
huawei/laya-al00ep_firmware < 10.1.0.160\(c786e160r3p8\)
huawei/mate_20_firmware < 10.1.0.160\(c00e160r3p8\)
huawei/mate_20_pro_firmware < 10.1.0.270\(c432e7r1p5\)
huawei/mate_20_x_firmware < 10.1.0.160\(c00e160r2p8\)
huawei/p30_firmware 9.1.0.272\(c635e4r2p2\)
huawei/p30_firmware < 10.1.0.123\(c432e22r2p5\)
huawei/p30_pro_firmware < 10.1.0.160\(c00e160r2p8\)
huawei/princeton-al10b_firmware < 10.1.0.160\(c00e160r2p11\)
... and 4 more
Published Dec 07, 2020
Tracked Since Feb 18, 2026