SB2020051409 - Improper Authentication in Huawei P20



SB2020051409 - Improper Authentication in Huawei P20

Published: May 14, 2020

Security Bulletin ID SB2020051409
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: CVE-2020-9073)

The vulnerability allows a local attacker to bypass authentication process.

The vulnerability exists due to the affected software insufficiently validate the user's identity when an user wants to do certain operation. An attacker with physical access can bypass the limit of student mode function.


Remediation

Install update from vendor's website.