Vulnerability Name: | CVE-2020-9076 (CCN-183238) |
Assigned: | 2020-06-10 |
Published: | 2020-06-10 |
Updated: | 2020-06-20 |
Summary: | HUAWEI P30;HUAWEI P30 Pro;Tony-AL00B smartphones with versions earlier than 10.1.0.135(C00E135R2P11); versions earlier than 10.1.0.135(C00E135R2P8), versions earlier than 10.1.0.135 have an improper authentication vulnerability. Due to the identity of the message sender not being properly verified, an attacker can exploit this vulnerability through man-in-the-middle attack to induce user to access malicious URL.
|
CVSS v3 Severity: | 6.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N) 5.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): High Privileges Required (PR): None User Interaction (UI): Required | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): High Integrity (I): High Availibility (A): None | 3.1 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N) 2.7 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): High Privileges Required (PR): None User Interaction (UI): Required | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): None | 2.1 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Athentication (Au): Single_Instance
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None |
|
Vulnerability Type: | CWE-287
|
Vulnerability Consequences: | Bypass Security |
References: | Source: MITRE Type: CNA CVE-2020-9076
Source: XF Type: UNKNOWN huawei-cve20209076-sec-bypass(183238)
Source: CCN Type: huawei-sa-20200610-02-phone Improper Authentication Vulnerability in Some Huawei Smartphones
Source: MISC Type: Vendor Advisory https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200610-02-phone-en
|
Vulnerable Configuration: | Configuration 1: cpe:/o:huawei:p30_firmware:*:*:*:*:*:*:*:* (Version < 10.1.0.135(c00e135r2p11))AND cpe:/h:huawei:p30:-:*:*:*:*:*:*:* Configuration 2: cpe:/o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:* (Version < 10.1.0.135(c00e135r2p8))AND cpe:/h:huawei:p30_pro:-:*:*:*:*:*:*:* Configuration 3: cpe:/o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:* (Version < 10.1.0.135(c01e135r2p8))AND cpe:/h:huawei:p30_pro:-:*:*:*:*:*:*:* Configuration 4: cpe:/o:huawei:tony-al00b_firmware:*:*:*:*:*:*:*:* (Version < 10.1.0.137(c00e137r2p11))AND cpe:/h:huawei:tony-al00b:-:*:*:*:*:*:*:* Configuration CCN 1: cpe:/h:huawei:p30:-:*:*:*:*:*:*:*OR cpe:/h:huawei:p30_pro:-:*:*:*:*:*:*:*OR cpe:/h:huawei:tony-al00b:-:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |