CVE-2020-1872: Medium severity Huawei P10 Plus Firmware vulnerability
Huawei smart phones P10 Plus with versions earlier than 9.1.0.201(C01E75R1P12T8), earlier than 9.1.0.252(C185E2R1P9T8), earlier than 9.1.0.252(C432E4R1P9T8), and earlier than 9.1.0.255(C576E6R1P8T8) have a digital balance bypass vulnerability. When re-configuring the mobile phone at the digital balance mode, an attacker can perform some operations to bypass the startup wizard, and then open some switch. As a result, the digital balance function is bypassed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Huawei smart phones P10 Plusto a version that resolves this vulnerability.Fixed in 9.1.0.201(C01E75R1P12T8) - Upgrade
Upgrade
Huawei smart phones P10 Plusto a version that resolves this vulnerability.Fixed in 9.1.0.252(C185E2R1P9T8) - Upgrade
Upgrade
Huawei smart phones P10 Plusto a version that resolves this vulnerability.Fixed in 9.1.0.252(C432E4R1P9T8) - Upgrade
Upgrade
Huawei smart phones P10 Plusto a version that resolves this vulnerability.Fixed in 9.1.0.255(C576E6R1P8T8)
Event History
Frequently Asked Questions
What is CVE-2020-1872?
CVE-2020-1872 is a vulnerability that affects Huawei P10 Plus smartphones with versions earlier than 9.1.0.201(C01E75R1P12T8), 9.1.0.252(C185E2R1P9T8), 9.1.0.252(C432E4R1P9T8), and 9.1.0.255(C576E6R1P8T8), allowing for digital balance bypass.
How does CVE-2020-1872 affect Huawei P10 Plus smartphones?
CVE-2020-1872 allows an attacker to bypass the digital balance feature on Huawei P10 Plus smartphones with vulnerable software versions.
What is the severity of CVE-2020-1872?
CVE-2020-1872 has a severity rating of medium (4.6).
How can I fix CVE-2020-1872 on my Huawei P10 Plus smartphone?
To fix CVE-2020-1872, update your Huawei P10 Plus smartphone to version 9.1.0.201(C01E75R1P12T8), 9.1.0.252(C185E2R1P9T8), 9.1.0.252(C432E4R1P9T8), or 9.1.0.255(C576E6R1P8T8) or later.
Where can I find more information about CVE-2020-1872?
You can find more information about CVE-2020-1872 on the Huawei website: https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-01-digitalbalance-en