First published: Fri Aug 21 2020(Updated: )
HUAWEI P30 Pro smartphones with Versions earlier than 10.1.0.160(C00E160R2P8) have an out of bound read vulnerability. Some functions are lack of verification when they process some messages sent from other module. Attackers can exploit this vulnerability by send malicious message to cause out-of-bound read. This can compromise normal service.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P30 Pro Firmware | <10.1.0.160\(c00e160r2p8\) | |
HUAWEI P30 Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9096 is an out of bound read vulnerability in HUAWEI P30 Pro smartphones with versions earlier than 10.1.0.160(C00E160R2P8).
CVE-2020-9096 can be exploited by attackers to send malicious messages and cause out-of-bound reads in certain functions of HUAWEI P30 Pro smartphones with affected versions.
CVE-2020-9096 has a severity rating of 5.5 (medium).
To fix CVE-2020-9096, update your HUAWEI P30 Pro smartphone to version 10.1.0.160(C00E160R2P8) or later.
You can find more information about CVE-2020-9096 at the following link: [Huawei Security Advisories - CVE-2020-9096](https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200819-02-smartphone-en).