CVE-2020-9252: Path Traversal
HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Honor Magic2 smartphones versions earlier than 10.1.0.160(C00E160R2P11) have a path traversal vulnerability. The system does not sufficiently validate certain pathname from certain process, successful exploit could allow the attacker write files to a crafted path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9252?
The severity of CVE-2020-9252 is low with a CVSS score of 2.3.
Which devices are affected by CVE-2020-9252?
HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Honor Magic2 smartphones versions earlier than 10.1.0.160(C00E160R2P11) are affected by CVE-2020-9252.
What is the vulnerability in HUAWEI Mate 20 devices?
The vulnerability in HUAWEI Mate 20 devices is a path traversal vulnerability.
How can I fix CVE-2020-9252?
To fix CVE-2020-9252, update your HUAWEI Mate 20 device to version 10.1.0.160(C00E160R3P8) or later.
Where can I find more information about CVE-2020-9252?
You can find more information about CVE-2020-9252 on the Huawei website at https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200715-07-smartphone-en.