CVE-2020-9080
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
27/12/2024
Last modified:
10/01/2025
Description
There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specific input to exploit this vulnerability. Successful exploitation may lead to local privilege escalation. (Vulnerability ID: HWPSIRT-2020-05272)<br />
<br />
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9080.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:huawei:mate_20_pro_firmware:10.1.0.135\(c01e135r2p8\):*:*:*:*:*:*:* | ||
cpe:2.3:h:huawei:mate_20_pro:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:mate_20_pro_\(ud\)_firmware:10.1.0.135\(c00e135r3p8\):*:*:*:*:*:*:* | ||
cpe:2.3:h:huawei:mate_20_pro_\(ud\):-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:nova_5i_firmware:*:*:*:*:*:*:*:* | 10.0.0.125\(c01e123r7p3\) (excluding) | |
cpe:2.3:h:huawei:nova_5i:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page