← Back to CVE List
Vulnerability Intelligence Report

CVE-2020-1808

Honor 20;HONOR 20 PRO;Honor Magic2;HUAWEI Mate 20 X;HUAWEI P30;HUAWEI P30 Pro;Honor View 20 smartphones with versions earlier than 10.0.0.187(C00E60R4P11); versions earlier than 10.0.0.187(C00E60R4P11); versions earlier than 10.0.0.176(C00E60R2P11);9.1.0.135(C00E133R2P1); versions earlier than 10.1.0.123(C431E22R3P5), versions earlier than 10.1.0.126(C636E5R3P4), versions earlier than 10.1.0.160(C00E160R2P11); versions earlier than 10.1.0.126(C185E8R5P1), versions earlier than 10.1.0.126(C636E9R2P4), versions earlier than 10.1.0.160(C00E160R2P8); versions earlier than 10.0.0.179(C636E3R4P3), versions earlier than 10.0.0.180(C185E3R3P3), versions earlier than 10.0.0.180(C432E10R3P4), versions earlier than 10.0.0.181(C675E5R1P2) have an out of bound read vulnerability. The software reads data past the end of the intended buffer. The attacker tricks the user into installing a crafted application, successful exploit may cause information disclosure or service abnormal.

No Active Exploit Signals
CVSS Base Score
7.1
HIGH
EPSS Probability:0.54%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
huawei honor_view_20_firmware all
huawei honor_view_20 all
huawei honor_20_firmware all
huawei honor_20 all
huawei honor_20_pro_firmware all
huawei honor_20_pro all
huawei honor_magic2_firmware all
huawei honor_magic2 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.540%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHuawei Technologies · Vendor · China
Reserved2019-11-29T00:00:00
Published2020-05-15T13:55:05
Last Updated2024-08-04T06:46:30

LINK COPIED TO CLIPBOARD