CVE-2020-1838

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
06/07/2020
Last modified:
09/07/2020

Description

HUAWEI Mate 30 Pro with versions earlier than 10.1.0.150(C00E136R5P3) have is an improper authentication vulnerability. The device does not sufficiently validate certain credential of user's face, an attacker could craft the credential of the user, successful exploit could allow the attacker to pass the authentication with the crafted credential.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:mate_30_pro_firmware:*:*:*:*:*:*:*:* 10.1.0.150\(c00e136r5p3\) (excluding)
cpe:2.3:h:huawei:mate_30_pro:-:*:*:*:*:*:*:*