Improper Authorization in Huawei Mate 20 - CVE-2020-1797

 

Improper Authorization in Huawei Mate 20 - CVE-2020-1797

Published: May 27, 2020


Vulnerability identifier: #VU28294
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1797
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass authorization checks.

The vulnerability exists due to the affected system does not properly restrict certain operation in ADB mode. An attacker with physical access to the device can break the limit of digital balance function.


Affected software

Huawei Mate 20

How to mitigate CVE-2020-1797

Install updates from vendor's website.

Huawei Mate 20 - update to 10.0.0.185

External References

Related Security Bulletins