CVE-2020-9070
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
20/04/2020
Last modified:
21/07/2021
Description
Huawei smartphones Taurus-AL00B with versions earlier than 10.0.0.205(C00E201R7P2) have an improper authentication vulnerability. The software insufficiently validate the user's identity when a user wants to do certain operation. An attacker can trick user into installing a malicious application to exploit this vulnerability. Successful exploit may cause some information disclosure.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:taurus-al00b_firmware:*:*:*:*:*:*:*:* | 10.0.0.205\(c00e201r7p2\) (excluding) | |
| cpe:2.3:h:huawei:taurus-al00b:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



