CVE-2020-9258

MEDIUM

HUAWEI P30 Firmware < 10.1.0.135(C00E135R2P11) - Information Disclosure via Improper Input Validation

Title source: llm
STIX 2.1

Description

HUAWEI P30 smartphone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper input verification vulnerability. An attribution in a module is not set correctly and some verification is lacked. Attackers with local access can exploit this vulnerability by injecting malicious fragment. This may lead to user information leak.

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 8.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-20
Status published
Products (1)
huawei/p30_firmware < 10.1.0.135\(c00e135r2p11\)
Published Jul 10, 2020
Tracked Since Feb 18, 2026