CVE-2020-1839

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
06/07/2020
Last modified:
09/07/2020

Description

HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a race condition vulnerability. There is a timing window exists in which certain pointer members can be modified by another process that is operating concurrently, an attacker should trick the user into running a crafted application with high privilege, successful exploit could cause code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:mate_30_firmware:*:*:*:*:*:*:*:* 10.1.0.150\(c00e136r5p3\) (excluding)
cpe:2.3:h:huawei:mate_30:-:*:*:*:*:*:*:*