Improper Handling of Exceptional Conditions in Huawei products - CVE-2020-9074

 

Improper Handling of Exceptional Conditions in Huawei products - CVE-2020-9074

Published: June 5, 2020


Vulnerability identifier: #VU28747
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9074
CWE-ID:
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a component cannot deal with an exception correctly. A remote authenticated attacker can send a specially crafted message to affected phone and compromise its normal service.


Affected software

Huawei Honor 20 PRO
Honor V20
Huawei Honor 20

How to mitigate CVE-2020-9074

Install updates from vendor's website.

Huawei Honor 20 PRO - addressed in versions 10.0.0.194(C636E3R3P1), 10.0.0.194(C10E3R3P2), 10.0.0.194(C432E9R5P1), 10.0.0.194(C00E62R8P12)
Honor V20 - addressed in versions 10.0.0.195(C00E62R4P11), 10.0.0.200(C185E3R3P3), 10.0.0.201(C10E5R4P3), 10.0.0.201(C636E3R4P3)
Huawei Honor 20 - addressed in versions 10.0.0.186(C185E2R2P1), 10.0.0.194(C432E9R5P1)

External References

Related Security Bulletins