SB2020052716 - Improper Authentication in Huawei Honor 9X
Published: May 27, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2020-1833)
The vulnerability allows a local attacker to bypass authentication process.
The vulnerability exists due to a logic error occurs when handling clock function. An attacker with physical access can do a series of crafted operations quickly before the phone is unlocked an gain access to clock information without unlock the phone.
Remediation
Install update from vendor's website.