Improper Handling of Exceptional Conditions in Huawei products - CVE-2020-9074
Published: June 5, 2020
Vulnerability identifier: #VU28747
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9074
CWE-ID:
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a component cannot deal with an exception correctly. A remote authenticated attacker can send a specially crafted message to affected phone and compromise its normal service.
Affected software
Huawei Honor 20 PRO
Honor V20
Huawei Honor 20
Honor V20
Huawei Honor 20
How to mitigate CVE-2020-9074
Install updates from vendor's website.
Huawei Honor 20 PRO - addressed in versions 10.0.0.194(C636E3R3P1), 10.0.0.194(C10E3R3P2), 10.0.0.194(C432E9R5P1), 10.0.0.194(C00E62R8P12)
Honor V20 - addressed in versions 10.0.0.195(C00E62R4P11), 10.0.0.200(C185E3R3P3), 10.0.0.201(C10E5R4P3), 10.0.0.201(C636E3R4P3)
Huawei Honor 20 - addressed in versions 10.0.0.186(C185E2R2P1), 10.0.0.194(C432E9R5P1)
Honor V20 - addressed in versions 10.0.0.195(C00E62R4P11), 10.0.0.200(C185E3R3P3), 10.0.0.201(C10E5R4P3), 10.0.0.201(C636E3R4P3)
Huawei Honor 20 - addressed in versions 10.0.0.186(C185E2R2P1), 10.0.0.194(C432E9R5P1)