CVE-2020-1882: Medium severity Huawei Mate 20 Rs Firmware vulnerability
Huawei mobile phones Ever-L29B versions earlier than 10.0.0.180(C185E6R3P3), earlier than 10.0.0.180(C432E6R1P7), earlier than 10.0.0.180(C636E5R2P3); HUAWEI Mate 20 RS versions earlier than 10.0.0.175(C786E70R3P8); HUAWEI Mate 20 X versions earlier than 10.0.0.176(C00E70R2P8); and Honor Magic2 versions earlier than 10.0.0.175(C00E59R2P11) have an improper authorization vulnerability. Due to improper authorization of some function, attackers can bypass the authorization to perform some operations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Huawei mobile phones Ever-L29Bto a version that resolves this vulnerability.Fixed in 10.0.0.180(C185E6R3P3) - Upgrade
Upgrade
Huawei mobile phones Ever-L29Bto a version that resolves this vulnerability.Fixed in 10.0.0.180(C432E6R1P7) - Upgrade
Upgrade
Huawei mobile phones Ever-L29Bto a version that resolves this vulnerability.Fixed in 10.0.0.180(C636E5R2P3) - Upgrade
Upgrade
HUAWEI Mate 20 RSto a version that resolves this vulnerability.Fixed in 10.0.0.175(C786E70R3P8) - Upgrade
Upgrade
HUAWEI Mate 20 Xto a version that resolves this vulnerability.Fixed in 10.0.0.176(C00E70R2P8) - Upgrade
Upgrade
Honor Magic2to a version that resolves this vulnerability.Fixed in 10.0.0.175(C00E59R2P11)
Event History
Frequently Asked Questions
What is the vulnerability ID for this Huawei mobile phone vulnerability?
The vulnerability ID for this Huawei mobile phone vulnerability is CVE-2020-1882.
Which models of Huawei mobile phones are affected by this vulnerability?
Huawei mobile phones Ever-L29B versions earlier than 10.0.0.180(C185E6R3P3), earlier than 10.0.0.180(C432E6R1P7), earlier than 10.0.0.180(C636E5R2P3); HUAWEI Mate 20 RS versions earlier than 10.0.0.175(C786E70R3P8); HUAWEI Mate 20 X versions earlier than 10.0.0.176(C00E70R2P8); and Honor Magic2 versions earlier than 10.0.0.175(C00E59R2P11) are affected by this vulnerability.
What is the severity of CVE-2020-1882?
The severity of CVE-2020-1882 is medium, with a severity score of 4.6.
How can I fix the CVE-2020-1882 vulnerability on my Huawei mobile phone?
To fix the CVE-2020-1882 vulnerability on your Huawei mobile phone, update to version 10.0.0.180(C185E6R3P3), 10.0.0.180(C432E6R1P7), 10.0.0.180(C636E5R2P3) for Ever-L29B models; 10.0.0.175(C786E70R3P8) for Mate 20 RS models; 10.0.0.176(C00E70R2P8) for Mate 20 X models; and 10.0.0.176(C00E59R2P11) for Honor Magic2 models.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Huawei website at http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200122-01-phone-en.