Improper Authentication in Huawei Mate 20 and Huawei Mate 30 Pro - CVE-2020-1794

 

Improper Authentication in Huawei Mate 20 and Huawei Mate 30 Pro - CVE-2020-1794

Published: March 19, 2020


Vulnerability identifier: #VU26215
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1794
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass authentication process.

The vulnerability exists due to the applock does not perform a sufficient authentication in certain scenarios. An attacker with physical access can bypass authentication process and gain certain data of the application which is locked.


Affected software

Huawei Mate 20
Huawei Mate 30 Pro

How to mitigate CVE-2020-1794

Install updates from vendor's website.

Huawei Mate 20 - update to 10.0.0.188
Huawei Mate 30 Pro - update to 10.0.0.203

External References

Related Security Bulletins