CVE-2020-1796: Medium severity Huawei Mate 20 Firmware vulnerability
There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successful exploit could allow a low privilege user to do certain operation which the user are supposed not to do.Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HUAWEI Mate 20to a version that resolves this vulnerability.Fixed in 10.0.0.188Patch C00E74R3P8 - Upgrade
Upgrade
HUAWEI Mate 30 Proto a version that resolves this vulnerability.Fixed in 10.0.0.203Patch C00E202R7P2
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-1796.
What is the severity of CVE-2020-1796?
The severity of CVE-2020-1796 is medium with a CVSS score of 6.6.
Which smartphones are affected by this vulnerability?
This vulnerability affects Huawei Mate 20 and Huawei Mate 30 Pro smartphones.
How does the vulnerability manifest?
The vulnerability allows a low privilege user to perform certain unauthorized operations on the affected smartphones.
Is there a fix available for CVE-2020-1796?
Please refer to the official Huawei security advisory for information on available fixes.