CVE-2020-1795: Low severity Huawei Mate 20 Firmware vulnerability
There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Digital Balance limit after a series of operations.Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HUAWEI Mate 20to a version that resolves this vulnerability.Fixed in 10.0.0.188Patch C00E74R3P8 - Upgrade
Upgrade
HUAWEI Mate 30 Proto a version that resolves this vulnerability.Fixed in 10.0.0.203Patch C00E202R7P2
Event History
Frequently Asked Questions
What is CVE-2020-1795?
CVE-2020-1795 is a logic error vulnerability in several smartphones that allows an attacker to bypass the Digital Balance limit after a series of operations.
Which smartphones are affected by CVE-2020-1795?
CVE-2020-1795 affects Huawei Mate 20 and Huawei Mate 30 Pro smartphones.
What is the severity of CVE-2020-1795?
CVE-2020-1795 has a severity rating of low, with a CVSS score of 2.4.
How can an attacker exploit CVE-2020-1795?
An attacker can exploit CVE-2020-1795 by performing a series of operations to bypass the Digital Balance limit on the affected smartphones.
Is there a patch or fix available for CVE-2020-1795?
Patch or fix information for CVE-2020-1795 can be found in the security advisory provided by Huawei: [link](https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200318-04-smartphone-en).