CVE-2020-9247 Information
Jun 07, 2022
cve
Description
There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege successful exploit may cause code execution. Affected product include Huawei HONOR 20 PRO Mate 20 Mate 20 Pro Mate 20 X P30 P30 Pro Hima-L29C Laya-AL00EP Princeton-AL10B Tony-AL00B Yale-L61A Yale-TL00B and YaleP-AL10B.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200729-03-smartphone-en
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: