René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

117 lines
3.6 KiB
JSON

{
"id": "CVE-2020-9237",
"sourceIdentifier": "psirt@huawei.com",
"published": "2020-08-17T16:15:14.013",
"lastModified": "2020-08-19T20:13:58.007",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Huawei smartphone Taurus-AL00B with versions earlier than 10.1.0.126(C00E125R5P3) have a user after free vulnerability. A module is lack of lock protection. Attackers can exploit this vulnerability by launching specific request. This could compromise normal service of the affected device."
},
{
"lang": "es",
"value": "Un tel\u00e9fono inteligente Huawei Taurus-AL00B con versiones anteriores a 10.1.0.126(C00E125R5P3), presenta una vulnerabilidad de uso de la memoria previamente liberada. Un m\u00f3dulo presenta una falta de protecci\u00f3n de bloqueo. Los atacantes pueden explotar esta vulnerabilidad al iniciar una petici\u00f3n espec\u00edfica. Esto podr\u00eda comprometer el servicio normal del dispositivo afectado."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 6.7,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.8,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 4.6
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 3.9,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-416"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:huawei:taurus-al00b_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.1.0.126\\(c00e125r5p3\\)",
"matchCriteriaId": "A84B9F7A-DB9B-42B5-BE2B-D661FBA0186F"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:huawei:taurus-al00b:-:*:*:*:*:*:*:*",
"matchCriteriaId": "89BEAD51-0413-4082-9EDE-9E252FF32A4F"
}
]
}
]
}
],
"references": [
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200812-02-smartphone-en",
"source": "psirt@huawei.com",
"tags": [
"Vendor Advisory"
]
}
]
}