First published: Fri Jan 03 2020(Updated: )
Mate 10 Pro;Honor V10;Honor 10;Nova 4 smartphones have a denial of service vulnerability. The system does not properly check the status of certain module during certain operations, an attacker should trick the user into installing a malicious application, successful exploit could cause reboot of the smartphone.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Mate 10 Pro Firmware | <9.1.0.321\(c605e4r1p13t8\) | |
Huawei Mate 10 pro | ||
Huawei Mate 10 Pro Firmware | <9.1.0.321\(c636e4r1p14t8\) | |
Huawei Mate 10 Pro Firmware | <9.1.0.330\(c432e6r1p12t8\) | |
Huawei Honor V10 Firmware | <9.1.0.333\(c00e333r2p1t8\) | |
Huawei Honor V10 | ||
Huawei Honor V10 Firmware | <9.1.0.350\(c636e4r1p13t8\) | |
Huawei Honor V10 Firmware | <9.1.0.351\(c432e5r1p13t8\) | |
Huawei Honor 10 Firmware | <9.1.0.350\(c10e5r1p14t8\) | |
Huawei Honor 10 | ||
Huawei Honor 10 Firmware | <9.1.0.350\(c185e3r1p12t8\) | |
Huawei Honor 10 Firmware | <9.1.0.350\(c461e3r1p11t8\) | |
Huawei Honor 10 Firmware | <9.1.0.350\(c636e3r1p13t8\) | |
Huawei Honor 10 Firmware | <9.1.0.351\(c432e5r1p13t8\) | |
Apple iOS | <9.1.0.225\(c636e1r4p1\) | |
HUAWEI nova 4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1785 is a denial of service vulnerability affecting Mate 10 Pro, Honor V10, Honor 10, and Nova 4 smartphones.
CVE-2020-1785 can cause a reboot of the affected devices when a certain module's status is not properly checked during certain operations.
An attacker can exploit CVE-2020-1785 by tricking the user into installing a malicious application.
CVE-2020-1785 has a high severity rating of 5.5.
Yes, Huawei has released a security advisory with information on mitigations and updates to address CVE-2020-1785.