CVE-2020-9081
Severity CVSS v4.0:
Pending analysis
Type:
CWE-285
Improper Authorization
Publication date:
27/12/2024
Last modified:
10/01/2025
Description
There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144)<br />
<br />
<br />
<br />
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081.
Impact
Base Score 3.x
3.50
Severity 3.x
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:* | 10.1.0.160\(c00e160r3p8\) (excluding) | |
cpe:2.3:h:huawei:mate_20:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:* | 10.1.0.160\(c00e160r2p11\) (excluding) | |
cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:* | 10.1.0.160\(c00e160r2p8\) (excluding) | |
cpe:2.3:h:huawei:p30_pro:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:princeton-al10d_firmware:*:*:*:*:*:*:*:* | 10.1.0.160\(c00e160r2p11\) (excluding) | |
cpe:2.3:h:huawei:princeton-al10d:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:yale-al00a_firmware:*:*:*:*:*:*:*:* | 10.1.0.160\(c00e160r8p12\) (excluding) | |
cpe:2.3:h:huawei:yale-al00a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:yale-al50a_firmware:*:*:*:*:*:*:*:* | 10.1.0.88\(c00e88r8p1\) (excluding) | |
cpe:2.3:h:huawei:yale-al50a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:yalep-al10b_firmware:*:*:*:*:*:*:*:* | 10.1.0.160\(c00e160r8p12\) (excluding) | |
cpe:2.3:h:huawei:yalep-al10b:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:* | 10.1.0.160\(c01e160r2p8\) (excluding) |
To consult the complete list of CPE names with products and versions, see this page