{ "id": "CVE-2020-9259", "sourceIdentifier": "psirt@huawei.com", "published": "2020-07-17T23:15:11.833", "lastModified": "2020-07-22T19:36:59.233", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Huawei Honor V30 smartphones with versions earlier than 10.1.0.212(C00E210R5P1) have an improper authentication vulnerability. The system does not sufficiently validate certain parameter passed from the bottom level, the attacker should trick the user into installing a malicious application and control the bottom level, successful exploit could cause information disclosure." }, { "lang": "es", "value": "Los tel\u00e9fonos inteligentes Huawei Honor V30 con versiones anteriores a 10.1.0.212(C00E210R5P1), presentan una vulnerabilidad de autenticaci\u00f3n inapropiada. El sistema no comprueba suficientemente determinados par\u00e1metros pasados ??desde el nivel inferior, el atacante debe enga\u00f1ar al usuario para que instale una aplicaci\u00f3n maliciosa y controlar el nivel inferior, una explotaci\u00f3n con \u00e9xito podr\u00eda causar una divulgaci\u00f3n de informaci\u00f3n" } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 2.8, "impactScore": 3.6 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-287" } ] } ], "configurations": [ { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:huawei:honor_v30_firmware:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.1.0.212\\(c00e210r5p1\\)", "matchCriteriaId": "D2FFE79F-8E1F-44F7-9BBC-9348A7C9DB19" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:huawei:honor_v30:-:*:*:*:*:*:*:*", "matchCriteriaId": "A90E11A8-FDDC-4F27-BA4F-52E158FAD83C" } ] } ] } ], "references": [ { "url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200715-02-smartphone-en", "source": "psirt@huawei.com", "tags": [ "Vendor Advisory" ] } ] }