CVE-2020-1794

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
20/03/2020
Last modified:
24/03/2020

Description

There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:* 10.0.0.188\(c00e74r3p8\) (excluding)
cpe:2.3:h:huawei:mate_20:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:mate_30_pro_firmware:*:*:*:*:*:*:*:* 10.0.0.203\(c00e202r7p2\) (excluding)
cpe:2.3:h:huawei:mate_30_pro:-:*:*:*:*:*:*:*