Vulnerabilites related to Huawei - HONOR 20 PRO
CVE-2020-9247 (GCVE-0-2020-9247)
Vulnerability from cvelistv5
Published
2020-12-07 12:49
Modified
2024-08-04 10:19
Severity ?
CWE
Summary
There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code execution. Affected product include Huawei HONOR 20 PRO, Mate 20, Mate 20 Pro, Mate 20 X, P30, P30 Pro, Hima-L29C, Laya-AL00EP, Princeton-AL10B, Tony-AL00B, Yale-L61A, Yale-TL00B and YaleP-AL10B.
Impacted products
Vendor Product Version
Huawei HONOR 20 PRO Version: unspecified   < 10.1.0.230(C432E9R5P1)
Version: unspecified   < 10.1.0.231(C10E3R3P2)
Create a notification for this product.
   Huawei HUAWEI Mate 20 Version: unspecified   < 10.1.0.160(C00E160R3P8)
Create a notification for this product.
   Huawei HUAWEI Mate 20 Pro Version: unspecified   < 10.1.0.270(C432E7R1P5)
Version: unspecified   < 10.1.0.270(C635E3R1P5)
Version: unspecified   < 10.1.0.273(C185E7R2P4)
Version: unspecified   < 10.1.0.273(C636E7R2P4)
Version: unspecified   < 10.1.0.277(C10E7R2P4)
Version: unspecified   < 10.1.0.277(C605E7R1P5)
Create a notification for this product.
   Huawei HUAWEI Mate 20 X Version: unspecified   < 10.1.0.160(C00E160R2P8)
Create a notification for this product.
   Huawei HUAWEI P30 Version: 9.1.0.272(C635E4R2P2)
Version: unspecified   < 10.1.0.123(C432E22R2P5)
Version: unspecified   < 10.1.0.126(C10E7R5P1)
Version: unspecified   < 10.1.0.126(C185E4R7P1)
Version: unspecified   < 10.1.0.126(C605E19R1P3)
Version: unspecified   < 10.1.0.126(C636E5R3P4)
Version: unspecified   < 10.1.0.126(C636E7R3P4)
Create a notification for this product.
   Huawei HUAWEI P30 Pro Version: unspecified   < 10.1.0.160(C00E160R2P8)
Create a notification for this product.
   Huawei Hima-L29C Version: unspecified   < 10.1.0.273(C185E5R2P4)
Version: unspecified   < 10.1.0.273(C636E5R2P4)
Version: unspecified   < 10.1.0.275(C10E4R2P4)
Create a notification for this product.
   Huawei Laya-AL00EP Version: unspecified   < 10.1.0.160(C786E160R3P8)
Create a notification for this product.
   Huawei Princeton-AL10B Version: unspecified   < 10.1.0.160(C00E160R2P11)
Create a notification for this product.
   Huawei Tony-AL00B Version: unspecified   < 10.1.0.160(C00E160R2P11)
Create a notification for this product.
   Huawei Yale-L61A Version: unspecified   < 10.1.0.225(C432E3R1P2)
Version: unspecified   < 10.1.0.226(C10E3R1P1)
Create a notification for this product.
   Huawei Yale-TL00B Version: unspecified   < 10.1.0.160(C01E160R8P12)
Create a notification for this product.
   Huawei YaleP-AL10B Version: unspecified   < 10.1.0.160(C00E160R8P12)
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-04T10:19:20.138Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200729-03-smartphone-en"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "HONOR 20 PRO",
          "vendor": "Huawei",
          "versions": [
            {
              "lessThan": "10.1.0.230(C432E9R5P1)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.231(C10E3R3P2)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "HUAWEI Mate 20",
          "vendor": "Huawei",
          "versions": [
            {
              "lessThan": "10.1.0.160(C00E160R3P8)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "HUAWEI Mate 20 Pro",
          "vendor": "Huawei",
          "versions": [
            {
              "lessThan": "10.1.0.270(C432E7R1P5)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.270(C635E3R1P5)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.273(C185E7R2P4)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.273(C636E7R2P4)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.277(C10E7R2P4)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.277(C605E7R1P5)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "HUAWEI Mate 20 X",
          "vendor": "Huawei",
          "versions": [
            {
              "lessThan": "10.1.0.160(C00E160R2P8)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "HUAWEI P30",
          "vendor": "Huawei",
          "versions": [
            {
              "status": "affected",
              "version": "9.1.0.272(C635E4R2P2)"
            },
            {
              "lessThan": "10.1.0.123(C432E22R2P5)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.126(C10E7R5P1)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.126(C185E4R7P1)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.126(C605E19R1P3)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.126(C636E5R3P4)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.126(C636E7R3P4)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "HUAWEI P30 Pro",
          "vendor": "Huawei",
          "versions": [
            {
              "lessThan": "10.1.0.160(C00E160R2P8)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "Hima-L29C",
          "vendor": "Huawei",
          "versions": [
            {
              "lessThan": "10.1.0.273(C185E5R2P4)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.273(C636E5R2P4)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.275(C10E4R2P4)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "Laya-AL00EP",
          "vendor": "Huawei",
          "versions": [
            {
              "lessThan": "10.1.0.160(C786E160R3P8)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "Princeton-AL10B",
          "vendor": "Huawei",
          "versions": [
            {
              "lessThan": "10.1.0.160(C00E160R2P11)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "Tony-AL00B",
          "vendor": "Huawei",
          "versions": [
            {
              "lessThan": "10.1.0.160(C00E160R2P11)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "Yale-L61A",
          "vendor": "Huawei",
          "versions": [
            {
              "lessThan": "10.1.0.225(C432E3R1P2)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            },
            {
              "lessThan": "10.1.0.226(C10E3R1P1)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "Yale-TL00B",
          "vendor": "Huawei",
          "versions": [
            {
              "lessThan": "10.1.0.160(C01E160R8P12)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        },
        {
          "product": "YaleP-AL10B",
          "vendor": "Huawei",
          "versions": [
            {
              "lessThan": "10.1.0.160(C00E160R8P12)",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code execution. Affected product include Huawei HONOR 20 PRO, Mate 20, Mate 20 Pro, Mate 20 X, P30, P30 Pro, Hima-L29C, Laya-AL00EP, Princeton-AL10B, Tony-AL00B, Yale-L61A, Yale-TL00B and YaleP-AL10B."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-120",
              "description": "CWE-120 Buffer Overflow",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2020-12-07T12:49:00",
        "orgId": "25ac1063-e409-4190-8079-24548c77ea2e",
        "shortName": "huawei"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200729-03-smartphone-en"
        }
      ],
      "source": {
        "advisory": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200729-03-smartphone-en",
        "discovery": "UNKNOWN"
      },
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "psirt@huawei.com",
          "ID": "CVE-2020-9247",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "HONOR 20 PRO",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.230(C432E9R5P1)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.231(C10E3R3P2)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "HUAWEI Mate 20",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.160(C00E160R3P8)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "HUAWEI Mate 20 Pro",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.270(C432E7R1P5)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.270(C635E3R1P5)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.273(C185E7R2P4)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.273(C636E7R2P4)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.277(C10E7R2P4)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.277(C605E7R1P5)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "HUAWEI Mate 20 X",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.160(C00E160R2P8)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "HUAWEI P30",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_value": "9.1.0.272(C635E4R2P2)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.123(C432E22R2P5)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.126(C10E7R5P1)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.126(C185E4R7P1)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.126(C605E19R1P3)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.126(C636E5R3P4)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.126(C636E7R3P4)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "HUAWEI P30 Pro",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.160(C00E160R2P8)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Hima-L29C",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.273(C185E5R2P4)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.273(C636E5R2P4)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.275(C10E4R2P4)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Laya-AL00EP",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.160(C786E160R3P8)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Princeton-AL10B",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.160(C00E160R2P11)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Tony-AL00B",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.160(C00E160R2P11)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Yale-L61A",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.225(C432E3R1P2)"
                          },
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.226(C10E3R1P1)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "Yale-TL00B",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.160(C01E160R8P12)"
                          }
                        ]
                      }
                    },
                    {
                      "product_name": "YaleP-AL10B",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "\u003c",
                            "version_value": "10.1.0.160(C00E160R8P12)"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Huawei"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code execution. Affected product include Huawei HONOR 20 PRO, Mate 20, Mate 20 Pro, Mate 20 X, P30, P30 Pro, Hima-L29C, Laya-AL00EP, Princeton-AL10B, Tony-AL00B, Yale-L61A, Yale-TL00B and YaleP-AL10B."
            }
          ]
        },
        "generator": {
          "engine": "Vulnogram 0.0.9"
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-120 Buffer Overflow"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200729-03-smartphone-en",
              "refsource": "MISC",
              "url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200729-03-smartphone-en"
            }
          ]
        },
        "source": {
          "advisory": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200729-03-smartphone-en",
          "discovery": "UNKNOWN"
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "25ac1063-e409-4190-8079-24548c77ea2e",
    "assignerShortName": "huawei",
    "cveId": "CVE-2020-9247",
    "datePublished": "2020-12-07T12:49:00",
    "dateReserved": "2020-02-18T00:00:00",
    "dateUpdated": "2024-08-04T10:19:20.138Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}