CVE-2020-1794
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
20/03/2020
Last modified:
24/03/2020
Description
There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).
Impact
Base Score 3.x
4.60
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:* | 10.0.0.188\(c00e74r3p8\) (excluding) | |
| cpe:2.3:h:huawei:mate_20:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:mate_30_pro_firmware:*:*:*:*:*:*:*:* | 10.0.0.203\(c00e202r7p2\) (excluding) | |
| cpe:2.3:h:huawei:mate_30_pro:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



