CVE-2020-9081

Severity CVSS v4.0:
Pending analysis
Type:
CWE-285 Improper Authorization
Publication date:
27/12/2024
Last modified:
10/01/2025

Description

There is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to exploit this vulnerability. Successful exploit could allow the attacker to bypass app lock. (Vulnerability ID: HWPSIRT-2019-12144)<br /> <br /> <br /> <br /> This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9081.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:* 10.1.0.160\(c00e160r3p8\) (excluding)
cpe:2.3:h:huawei:mate_20:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:* 10.1.0.160\(c00e160r2p11\) (excluding)
cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:* 10.1.0.160\(c00e160r2p8\) (excluding)
cpe:2.3:h:huawei:p30_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:princeton-al10d_firmware:*:*:*:*:*:*:*:* 10.1.0.160\(c00e160r2p11\) (excluding)
cpe:2.3:h:huawei:princeton-al10d:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:yale-al00a_firmware:*:*:*:*:*:*:*:* 10.1.0.160\(c00e160r8p12\) (excluding)
cpe:2.3:h:huawei:yale-al00a:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:yale-al50a_firmware:*:*:*:*:*:*:*:* 10.1.0.88\(c00e88r8p1\) (excluding)
cpe:2.3:h:huawei:yale-al50a:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:yalep-al10b_firmware:*:*:*:*:*:*:*:* 10.1.0.160\(c00e160r8p12\) (excluding)
cpe:2.3:h:huawei:yalep-al10b:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:* 10.1.0.160\(c01e160r2p8\) (excluding)