There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful exploitation may impact the service. (Vulnerability ID: HWPSIRT-2019-12302)
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9250.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Huawei
Huawei mate 20 Pro Huawei mate 20 Pro Firmware |
|
| CPEs | cpe:2.3:h:huawei:mate_20_pro:-:*:*:*:*:*:*:* cpe:2.3:o:huawei:mate_20_pro_firmware:10.1.0.160\(c00e160r3p8\):*:*:*:*:*:*:* |
|
| Vendors & Products |
Huawei
Huawei mate 20 Pro Huawei mate 20 Pro Firmware |
Fri, 20 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-522 | |
| Metrics |
ssvc
|
Fri, 20 Dec 2024 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful exploitation may impact the service. (Vulnerability ID: HWPSIRT-2019-12302) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9250. | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: huawei
Published: 2024-12-20T01:50:07.201Z
Updated: 2024-12-20T17:14:55.905Z
Reserved: 2020-02-18T00:00:00.000Z
Link: CVE-2020-9250
Updated: 2024-12-20T17:14:50.645Z
Status : Analyzed
Published: 2024-12-20T02:15:05.150
Modified: 2025-07-11T14:33:07.873
Link: CVE-2020-9250
No data.