CVE-2020-9257

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
17/07/2020
Last modified:
22/07/2020

Description

HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.123(C432E19R2P5patch02), versions earlier than 10.1.0.126(C10E11R5P1), and versions earlier than 10.1.0.160(C00E160R2P8) have a buffer overflow vulnerability. The software access data past the end, or before the beginning, of the intended buffer when handling certain operations of certificate, the attacker should trick the user into installing a malicious application, successful exploit may cause code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:* 10.1.0.123\(c432e19r2p5patch02\) (excluding)
cpe:2.3:h:huawei:p30_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:* 10.1.0.126\(c10e11r5p1\) (excluding)
cpe:2.3:h:huawei:p30_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:* 10.1.0.160\(c00e160r2p8\) (excluding)
cpe:2.3:h:huawei:p30_pro:-:*:*:*:*:*:*:*