CVE-2020-1786: Medium severity Huawei Mate 20 Pro Firmware vulnerability
HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a special condition which could allow an attacker to forge a crafted application as a normal one. Successful exploit could allow the attacker to bypass digital balance function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HUAWEI Mate 20 Pro smartphonesto a version that resolves this vulnerability.Fixed in 10.0.0.175(C00E69R3P8)Patch C00E69R3P8
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2020-1786.
What is the title of this vulnerability?
The title of this vulnerability is 'HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability.'
What is the severity level of CVE-2020-1786?
The severity level of CVE-2020-1786 is medium with a score of 4.6.
Which software versions are affected by this vulnerability?
HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) are affected by this vulnerability.
How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker to forge a crafted application as a normal one.