First published: Mon Aug 17 2020(Updated: )
Huawei smartphone Taurus-AL00B with versions earlier than 10.1.0.126(C00E125R5P3) have a user after free vulnerability. A module is lack of lock protection. Attackers can exploit this vulnerability by launching specific request. This could compromise normal service of the affected device.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Taurus-al00b Firmware | <10.1.0.126\(c00e125r5p3\) | |
Huawei Taurus-al00b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-9237 is considered high due to the potential for attackers to exploit a user after free vulnerability.
To fix CVE-2020-9237, update your Huawei Taurus-AL00B firmware to version 10.1.0.126(C00E125R5P3) or later.
CVE-2020-9237 affects Huawei Taurus-AL00B devices with firmware versions earlier than 10.1.0.126(C00E125R5P3).
CVE-2020-9237 is classified as a user after free vulnerability caused by a lack of lock protection in a specific module.
Yes, CVE-2020-9237 can compromise the normal service of the affected device, potentially leading to further exploitation.