CVE-2020-9113

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
19/10/2020
Last modified:
22/10/2020

Description

HUAWEI Mate 20 versions earlier than 10.0.0.188(C00E74R3P8) have a buffer overflow vulnerability in the Bluetooth module. Due to insufficient input validation, an unauthenticated attacker may craft Bluetooth messages after successful paring, causing buffer overflow. Successful exploit may cause code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:* 10.0.0.188\(c00e74r3p8\) (excluding)
cpe:2.3:h:huawei:mate_20:-:*:*:*:*:*:*:*