René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

117 lines
3.8 KiB
JSON

{
"id": "CVE-2020-1788",
"sourceIdentifier": "psirt@huawei.com",
"published": "2020-01-21T23:15:13.647",
"lastModified": "2020-01-24T22:03:30.393",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not properly validate the identity of another application who would call its interface. An attacker could trick the user into installing a malicious application. Successful exploit could allow unauthorized actions leading to information disclosure."
},
{
"lang": "es",
"value": "Los tel\u00e9fonos inteligentes Honor V30 con versiones anteriores a 10.0.1.135(C00E130R4P1), presentan una vulnerabilidad de autenticaci\u00f3n inapropiada. Ciertas aplicaciones no comprueban apropiadamente la identidad de otra aplicaci\u00f3n que llamar\u00eda a su interfaz. Un atacante podr\u00eda enga\u00f1ar al usuario para que instale una aplicaci\u00f3n maliciosa. Una explotaci\u00f3n con \u00e9xito podr\u00eda permitir acciones no autorizadas que conllevan a una divulgaci\u00f3n de informaci\u00f3n."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.8,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:huawei:honor_v30_firmware:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.0.1.135\\(c00e130r4p1\\)",
"matchCriteriaId": "DC7FFDFA-2349-40EA-8DBD-F308CE72F005"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:huawei:honor_v30:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A90E11A8-FDDC-4F27-BA4F-52E158FAD83C"
}
]
}
]
}
],
"references": [
{
"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200115-02-smartphone-en",
"source": "psirt@huawei.com",
"tags": [
"Vendor Advisory"
]
}
]
}