There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code execution. Affected product include Huawei HONOR 20 PRO, Mate 20, Mate 20 Pro, Mate 20 X, P30, P30 Pro, Hima-L29C, Laya-AL00EP, Princeton-AL10B, Tony-AL00B, Yale-L61A, Yale-TL00B and YaleP-AL10B.

Project Subscriptions

Vendors Products
Hima-l29c Subscribe
Hima-l29c Firmware Subscribe
Honor 20 Pro Subscribe
Honor 20 Pro Firmware Subscribe
Laya-al00ep Subscribe
Laya-al00ep Firmware Subscribe
Mate 20 Subscribe
Mate 20 Firmware Subscribe
Mate 20 Pro Subscribe
Mate 20 Pro Firmware Subscribe
Mate 20 X Subscribe
Mate 20 X Firmware Subscribe
P30 Firmware Subscribe
P30 Pro Subscribe
P30 Pro Firmware Subscribe
Princeton-al10b Subscribe
Princeton-al10b Firmware Subscribe
Tony-al00b Subscribe
Tony-al00b Firmware Subscribe
Yale-l61a Subscribe
Yale-l61a Firmware Subscribe
Yale-tl00b Subscribe
Yale-tl00b Firmware Subscribe
Yalep-al10b Subscribe
Yalep-al10b Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-30076 There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code execution. Affected product include Huawei HONOR 20 PRO, Mate 20, Mate 20 Pro, Mate 20 X, P30, P30 Pro, Hima-L29C, Laya-AL00EP, Princeton-AL10B, Tony-AL00B, Yale-L61A, Yale-TL00B and YaleP-AL10B.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-04T10:19:20.138Z

Reserved: 2020-02-18T00:00:00

Link: CVE-2020-9247

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-07T13:15:11.123

Modified: 2024-11-21T05:40:15.980

Link: CVE-2020-9247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses