CVE-2020-1786
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
09/01/2020
Last modified:
15/01/2020
Description
HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a special condition which could allow an attacker to forge a crafted application as a normal one. Successful exploit could allow the attacker to bypass digital balance function.
Impact
Base Score 3.x
4.60
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:huawei:mate_20_pro_firmware:*:*:*:*:*:*:*:* | 10.0.0.175\(c00e69r3p8\) (excluding) | |
cpe:2.3:h:huawei:mate_20_pro:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page