First published: Tue Jan 21 2020(Updated: )
Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not properly validate the identity of another application who would call its interface. An attacker could trick the user into installing a malicious application. Successful exploit could allow unauthorized actions leading to information disclosure.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Honor V30 Firmware | <10.0.1.135\(c00e130r4p1\) | |
Huawei Honor V30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-1788.
The severity of CVE-2020-1788 is medium, with a score of 5.5.
Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) are affected.
The vulnerability allows an attacker to trick the user into installing a malicious application.
Yes, applying the latest firmware update, version 10.0.1.135(C00E130R4P1) or later, will fix the vulnerability.