Improper Authorization in Huawei Mate 20 - CVE-2020-9251

 

Improper Authorization in Huawei Mate 20 - CVE-2020-9251

Published: July 22, 2020


Vulnerability identifier: #VU31758
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9251
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to bypass authorization checks.

The vulnerability exists due to the affected software does not properly restrict certain operation in certain scenario. An attacker with physical access to the device can do certain configuration before the user turns on student mode function and bypass the limit of student mode function.


Affected software

Huawei Mate 20

How to mitigate CVE-2020-9251

Install updates from vendor's website.

Huawei Mate 20 - update to 10.1.0.160

External References

Related Security Bulletins