First published: Fri Jul 10 2020(Updated: )
HUAWEI P30 smartphone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper input verification vulnerability. An attribution in a module is not set correctly and some verification is lacked. Attackers with local access can exploit this vulnerability by injecting malicious fragment. This may lead to user information leak.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P30 Firmware | <10.1.0.135\(c00e135r2p11\) | |
HUAWEI P30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Huawei P30 smartphone vulnerability is CVE-2020-9258.
The severity of CVE-2020-9258 is medium.
This vulnerability affects Huawei P30 smartphones with versions earlier than 10.1.0.135(C00E135R2P11).
Attackers with local access can exploit this vulnerability by injecting malicious fragments.
It is recommended to update Huawei P30 smartphones to version 10.1.0.135(C00E135R2P11) to address this vulnerability.