First published: Mon Jul 06 2020(Updated: )
HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3) have a race condition vulnerability. There is a timing window exists in which certain pointer members can be modified by another process that is operating concurrently, an attacker should trick the user into running a crafted application with high privilege, successful exploit could cause code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Mate 30 Firmware | <10.1.0.150\(c00e136r5p3\) | |
HUAWEI Mate 30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1839 is a race condition vulnerability in HUAWEI Mate 30 with versions earlier than 10.1.0.150(C00E136R5P3).
CVE-2020-1839 can be exploited if an attacker tricks the user into running a crafted application, allowing the attacker to modify certain pointer members in the system.
CVE-2020-1839 has a severity score of 6.3, which is considered medium.
To fix CVE-2020-1839, you need to update your HUAWEI Mate 30 firmware to version 10.1.0.150(C00E136R5P3) or later.
You can find more information about CVE-2020-1839 in the security advisory [here](https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200701-04-smartphone-en).