CVE-2020-1839
Severity CVSS v4.0:
Pending analysis
Type:
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
06/07/2020
Last modified:
09/07/2020
Description
HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a race condition vulnerability. There is a timing window exists in which certain pointer members can be modified by another process that is operating concurrently, an attacker should trick the user into running a crafted application with high privilege, successful exploit could cause code execution.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
3.70
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:mate_30_firmware:*:*:*:*:*:*:*:* | 10.1.0.150\(c00e136r5p3\) (excluding) | |
| cpe:2.3:h:huawei:mate_30:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



