SB20200716105 - Multiple vulnerabilities in Huawei Smartphones
Published: July 16, 2020 Updated: August 27, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Path traversal (CVE-ID: CVE-2020-9252)
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A local administrator can send a specially crafted HTTP request and write files to a crafted path.
2) Improper Authorization (CVE-ID: CVE-2020-9251)
The vulnerability allows a local attacker to bypass authorization checks.
The vulnerability exists due to the affected software does not properly restrict certain operation in certain scenario. An attacker with physical access to the device can do certain configuration before the user turns on student mode function and bypass the limit of student mode function.
3) Information disclosure (CVE-ID: CVE-2020-9082)
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to the system has a logic judging error under certain scenario. An attacker with physical access can gain certain information from certain apps locked by Applock
Remediation
Install update from vendor's website.