First published: Tue Feb 18 2020(Updated: )
Huawei smart phones P10 Plus with versions earlier than 9.1.0.201(C01E75R1P12T8), earlier than 9.1.0.252(C185E2R1P9T8), earlier than 9.1.0.252(C432E4R1P9T8), and earlier than 9.1.0.255(C576E6R1P8T8) have a digital balance bypass vulnerability. When re-configuring the mobile phone at the digital balance mode, an attacker can perform some operations to bypass the startup wizard, and then open some switch. As a result, the digital balance function is bypassed.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P10 Plus Firmware | <9.1.0.201\(c01e75r1p12t8\) | |
Huawei P10 Plus | ||
Huawei P10 Plus Firmware | <9.1.0.252\(c185e2r1p9t8\) | |
Huawei P10 Plus Firmware | <9.1.0.252\(c432e4r1p9t8\) | |
Huawei P10 Plus Firmware | <9.1.0.255\(c576e6r1p8t8\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1872 is a vulnerability that affects Huawei P10 Plus smartphones with versions earlier than 9.1.0.201(C01E75R1P12T8), 9.1.0.252(C185E2R1P9T8), 9.1.0.252(C432E4R1P9T8), and 9.1.0.255(C576E6R1P8T8), allowing for digital balance bypass.
CVE-2020-1872 allows an attacker to bypass the digital balance feature on Huawei P10 Plus smartphones with vulnerable software versions.
CVE-2020-1872 has a severity rating of medium (4.6).
To fix CVE-2020-1872, update your Huawei P10 Plus smartphone to version 9.1.0.201(C01E75R1P12T8), 9.1.0.252(C185E2R1P9T8), 9.1.0.252(C432E4R1P9T8), or 9.1.0.255(C576E6R1P8T8) or later.
You can find more information about CVE-2020-1872 on the Huawei website: https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-01-digitalbalance-en