VYPR

Mate 30 Pro Firmware

by Huawei

CVEs (9)

  • CVE-2020-0022HigFeb 13, 2020
    risk 0.58cvss 8.8epss 0.06

    In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2020-1796MedMar 20, 2020
    risk 0.43cvss 6.6epss 0.00

    There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successful exploit could allow a low privilege user to do certain operation which the user are supposed not to do.Affected product…

  • CVE-2020-9256MedJul 18, 2020
    risk 0.42cvss 6.5epss 0.01

    Huawei Mate 30 Pro smartphones with versions earlier than 10.1.0.150(C00E136R5P3) have an improper authorization vulnerability. The system does not properly restrict the use of system service by applications, the attacker should trick the user into installing a malicious…

  • CVE-2020-9119MedDec 24, 2020
    risk 0.40cvss 6.2epss 0.00

    There is a privilege escalation vulnerability on some Huawei smart phones due to design defects. The attacker needs to physically contact the mobile phone and obtain higher privileges, and execute relevant commands, resulting in the user's privilege promotion.

  • CVE-2020-1838MedJul 6, 2020
    risk 0.36cvss 5.5epss 0.00

    HUAWEI Mate 30 Pro with versions earlier than 10.1.0.150(C00E136R5P3) have is an improper authentication vulnerability. The device does not sufficiently validate certain credential of user's face, an attacker could craft the credential of the user, successful exploit could allow…

  • CVE-2020-1801MedApr 10, 2020
    risk 0.36cvss 5.5epss 0.01

    There is an improper authentication vulnerability in several smartphones. Certain function interface in the system does not sufficiently validate the caller's identity in certain share scenario, successful exploit could cause information disclosure. Affected product versions…

  • CVE-2020-1794MedMar 20, 2020
    risk 0.30cvss 4.6epss 0.00

    There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions…

  • CVE-2020-1793MedMar 20, 2020
    risk 0.30cvss 4.6epss 0.00

    There is an improper authentication vulnerability in several smartphones. The applock does not perform a sufficient authentication in certain scenarios, successful exploit could allow the attacker to gain certain data of the application which is locked. Affected product versions…

  • CVE-2020-1795LowMar 20, 2020
    risk 0.16cvss 2.4epss 0.00

    There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation when the Digital Balance function is on. Successful exploit could allow the attacker to bypass the Digital Balance limit after a series of operations.Affected…