VYPR
Unrated severityNVD Advisory· Published Jul 17, 2020· Updated Aug 4, 2024

CVE-2020-9255

CVE-2020-9255

Description

Huawei Honor 10 smartphones with versions earlier than 10.0.0.178(C00E178R1P4) have a denial of service vulnerability. Certain service in the system does not sufficiently validate certain parameter which is received, the attacker should trick the user into installing a malicious application, successful exploit could cause a denial of service condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Denial of service vulnerability in Huawei Honor 10 due to insufficient parameter validation; requires malicious app installation.

Vulnerability

CVE-2020-9255 is a denial of service vulnerability in Huawei Honor 10 smartphones with versions earlier than 10.0.0.178(C00E178R1P4). The issue exists in a certain system service that does not sufficiently validate a specific parameter received, leading to a denial of service condition when exploited. [1]

Exploitation

To exploit this vulnerability, an attacker must trick the user into installing a malicious application. The attacker does not require any additional privileges or network access beyond the ability to deliver the malicious app. Once installed, the app sends crafted input to the vulnerable service, triggering the denial of service. [1]

Impact

Successful exploitation causes a denial of service condition, which may result in temporary unavailability of device services or features. The confidentiality and integrity of data are not directly affected. [1]

Mitigation

Huawei has released a software update to fix this vulnerability. The resolved version is 10.0.0.178(C00E178R1P4) for Honor 10. Users should update their devices to this version or later. No workarounds have been provided. [1]

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Huawei/Honor 10llm-fuzzy2 versions
    <10.0.0.178(C00E178R1P4)+ 1 more
    • (no CPE)range: <10.0.0.178(C00E178R1P4)
    • (no CPE)range: Versions earlier than 10.0.0.178(C00E178R1P4)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.