There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker need to gain certain information in the victim's smartphone to launch the attack, and successful exploit could cause information disclosure.Affected product versions include:HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8),versions earlier than 10.1.0.160(C01E160R2P8);HUAWEI Mate 20 X versions earlier than 10.1.0.160(C00E160R2P8),versions earlier than 10.1.0.160(C01E160R2P8);HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8);Laya-AL00EP versions earlier than 10.1.0.160(C786E160R3P8);Tony-AL00B versions earlier than 10.1.0.160(C00E160R2P11);Tony-TL00B versions earlier than 10.1.0.160(C01E160R2P11).

Project Subscriptions

Vendors Products
Laya-al00ep Subscribe
Laya-al00ep Firmware Subscribe
Mate 20 Subscribe
Mate 20 Firmware Subscribe
Mate 20 X Subscribe
Mate 20 X Firmware Subscribe
P30 Pro Subscribe
P30 Pro Firmware Subscribe
Tony-al00b Subscribe
Tony-al00b Firmware Subscribe
Tony-tl00b Subscribe
Tony-tl00b Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-29938 There is an information disclosure vulnerability in several smartphones. The device does not sufficiently validate the identity of smart wearable device in certain specific scenario, the attacker need to gain certain information in the victim's smartphone to launch the attack, and successful exploit could cause information disclosure.Affected product versions include:HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8),versions earlier than 10.1.0.160(C01E160R2P8);HUAWEI Mate 20 X versions earlier than 10.1.0.160(C00E160R2P8),versions earlier than 10.1.0.160(C01E160R2P8);HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8);Laya-AL00EP versions earlier than 10.1.0.160(C786E160R3P8);Tony-AL00B versions earlier than 10.1.0.160(C00E160R2P11);Tony-TL00B versions earlier than 10.1.0.160(C01E160R2P11).
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-04T10:19:19.969Z

Reserved: 2020-02-18T00:00:00

Link: CVE-2020-9109

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-10-12T14:15:14.340

Modified: 2024-11-21T05:40:03.407

Link: CVE-2020-9109

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses