CVE-2020-1833

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
29/05/2020
Last modified:
01/06/2020

Description

Honor 9X smartphones with versions earlier than 9.1.1.172(C00E170R8P1) have an improper authentication vulnerability. A logic error occurs when handling clock function, an attacker should do a series of crafted operations quickly before the phone is unlocked, successful exploit could allow the attacker to access clock information without unlock the phone.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:honor_9x_firmware:*:*:*:*:*:*:*:* 9.1.1.172\(c00e170r8p1\) (excluding)
cpe:2.3:h:huawei:honor_9x:-:*:*:*:*:*:*:*