First published: Tue Dec 29 2020(Updated: )
There is an out-of-bound read vulnerability in huawei smartphone Mate 30 versions earlier than 10.1.0.156 (C00E155R7P2). An attacker with specific permission can exploit this vulnerability by sending crafted packet with specific parameter to the target device. Due to insufficient validation of the parameter, successful exploit can cause the device to behave abnormally.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Mate 30 Firmware | <10.1.0.156\(c00e155r7p2\) | |
HUAWEI Mate 30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9125 is an out-of-bound read vulnerability in huawei smartphone Mate 30 versions earlier than 10.1.0.156 (C00E155R7P2).
An attacker with specific permission can exploit this vulnerability by sending crafted packet with specific parameter to the target device.
The severity of CVE-2020-9125 is medium with a CVSS score of 6.7.
Huawei smartphone Mate 30 versions earlier than 10.1.0.156 (C00E155R7P2) are affected by CVE-2020-9125.
To fix CVE-2020-9125, it is recommended to update the Huawei Mate 30 firmware to version 10.1.0.156 (C00E155R7P2) or later.