#VU29139 Information disclosure in Huawei Mate 30 - CVE-2020-1835

 

#VU29139 Information disclosure in Huawei Mate 30 - CVE-2020-1835

Published: June 18, 2020


Vulnerability identifier: #VU29139
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-1835
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Huawei Mate 30
Software vendor:
Huawei

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a logic judgment error when the system handling Bluetooth connections. A remote attacker on the local network can craft as an authenticated Bluetooth peer and gain unauthorized access to sensitive information on the system.


Remediation

Install updates from vendor's website.

External links