First published: Mon Oct 12 2020(Updated: )
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) have an information disclosure vulnerability. The device does not sufficiently validate the output of device in certain specific scenario, the attacker can gain information in the victim's smartphone to launch the attack, successful exploit could cause information disclosure.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Taurus-an00b Firmware | <10.1.0.156 | |
Huawei Taurus-an00b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9110 is an information disclosure vulnerability in Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2).
CVE-2020-9110 has a severity value of 4.6, which is considered medium.
CVE-2020-9110 allows an attacker to gain information on the victim's smartphone by exploiting a validation issue in certain scenarios.
Taurus-AN00B versions earlier than 10.1.0.156(C00E155R7P2) are affected by CVE-2020-9110.
To fix CVE-2020-9110, it is recommended to update your Taurus-AN00B firmware to version 10.1.0.156(C00E155R7P2) or later.