#VU26214 Improper Authentication in Huawei Mate 20 and Huawei Mate 30 Pro - CVE-2020-1793

 

#VU26214 Improper Authentication in Huawei Mate 20 and Huawei Mate 30 Pro - CVE-2020-1793

Published: March 19, 2020


Vulnerability identifier: #VU26214
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-1793
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Huawei Mate 20
Huawei Mate 30 Pro
Software vendor:
Huawei

Description

The vulnerability allows a local attacker to bypass authentication process.

The vulnerability exists due to the applock does not perform a sufficient authentication in certain scenarios. An attacker with physical access can bypass authentication process and gain certain data of the application which is locked.


Remediation

Install updates from vendor's website.

External links