CVE-2020-9104
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/08/2020
Last modified:
25/08/2020
Description
HUAWEI P30 smartphones with Versions earlier than 10.1.0.123(C431E22R2P5),Versions earlier than 10.1.0.123(C432E22R2P5),Versions earlier than 10.1.0.126(C10E7R5P1),Versions earlier than 10.1.0.126(C185E4R7P1),Versions earlier than 10.1.0.126(C461E7R3P1),Versions earlier than 10.1.0.126(C605E19R1P3),Versions earlier than 10.1.0.126(C636E7R3P4),Versions earlier than 10.1.0.128(C635E3R2P4),Versions earlier than 10.1.0.160(C00E160R2P11),Versions earlier than 10.1.0.160(C01E160R2P11) have a denial of service vulnerability. In specific scenario, due to the improper resource management and memory leak of some feature, the attacker could exploit this vulnerability to cause the device reset.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:* | 10.1.0.123\(c431e22r2p5\) (excluding) | |
| cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:* | 10.1.0.123\(c432e22r2p5\) (excluding) | |
| cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:* | 10.1.0.126\(c10e7r5p1\) (excluding) | |
| cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:* | 10.1.0.126\(c185e4r7p1\) (excluding) | |
| cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:* | 10.1.0.126\(c461e7r3p1\) (excluding) | |
| cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:* | 10.1.0.126\(c605e19r1p3\) (excluding) | |
| cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:* | 10.1.0.126\(c636e7r3p4\) (excluding) | |
| cpe:2.3:h:huawei:p30:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:* | 10.1.0.128\(c635e3r2p4\) (excluding) |
To consult the complete list of CPE names with products and versions, see this page



