CVE-2020-9140: Buffer Overflow
Published Jan 13, 2021
·Updated
There is a vulnerability with buffer access with incorrect length value in some Huawei Smartphone.Unauthorized users may trigger code execution when a buffer overflow occurs.
Affected Software
11 affected components
Huawei Emui=9.1.0
Huawei Emui=9.1.1
Huawei Emui=10.0.0
Huawei Emui=10.1.0
Huawei Emui=10.1.1
Huawei Emui=11.0.0
Huawei Magic Ui=2.1.1
Huawei Magic Ui=3.0.0
Huawei Magic Ui=3.1.0
Huawei Magic Ui=3.1.1
Huawei Magic Ui=4.0.0
Event History
Jan 13, 2021
CVE Published
via MITRE·09:55 PM
Data Sourced
via MITRE·09:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-9140?
CVE-2020-9140 is classified as a high-severity vulnerability due to potential code execution risks.
2
How do I fix CVE-2020-9140?
To fix CVE-2020-9140, users should update their Huawei devices to the latest version of EMUI or Magic UI as recommended by Huawei.
3
What devices are affected by CVE-2020-9140?
CVE-2020-9140 affects various versions of Huawei EMUI and Magic UI, specifically from 9.1.0 to 11.0.0 and 2.1.1 to 4.0.0.
4
What types of attacks can be executed through CVE-2020-9140?
CVE-2020-9140 allows unauthorized users to trigger code execution through buffer overflow attacks.
5
Is my Huawei smartphone vulnerable if it runs EMUI 10.1.1?
Yes, if your Huawei smartphone runs EMUI 10.1.1, it is affected by CVE-2020-9140 and should be updated to mitigate the risk.