First published: Mon Oct 12 2020(Updated: )
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. The system does not sufficiently validate certain pathname, successful exploit could allow the attacker access files and cause information disclosure.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P30 Pro Firmware | <10.1.0.160\(c00e160r2p8\) | |
HUAWEI P30 Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-9106.
The severity of CVE-2020-9106 is medium (CVSS score: 4.6).
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) are affected by CVE-2020-9106.
CVE-2020-9106 is a path traversal vulnerability that allows attackers to access files and cause information disclosure by exploiting a lack of validation on certain pathnames.
Yes, updating HUAWEI P30 Pro to version 10.1.0.160(C00E160R2P8) or later will fix the vulnerability CVE-2020-9106.