Description
There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code execution. Affected product include Huawei HONOR 20 PRO, Mate 20, Mate 20 Pro, Mate 20 X, P30, P30 Pro, Hima-L29C, Laya-AL00EP, Princeton-AL10B, Tony-AL00B, Yale-L61A, Yale-TL00B and YaleP-AL10B.
Published: 2020-12-07
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-30076 There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code execution. Affected product include Huawei HONOR 20 PRO, Mate 20, Mate 20 Pro, Mate 20 X, P30, P30 Pro, Hima-L29C, Laya-AL00EP, Princeton-AL10B, Tony-AL00B, Yale-L61A, Yale-TL00B and YaleP-AL10B.
History

No history.

Subscriptions

Huawei Hima-l29c Hima-l29c Firmware Honor 20 Pro Honor 20 Pro Firmware Laya-al00ep Laya-al00ep Firmware Mate 20 Mate 20 Firmware Mate 20 Pro Mate 20 Pro Firmware Mate 20 X Mate 20 X Firmware P30 P30 Firmware P30 Pro P30 Pro Firmware Princeton-al10b Princeton-al10b Firmware Tony-al00b Tony-al00b Firmware Yale-l61a Yale-l61a Firmware Yale-tl00b Yale-tl00b Firmware Yalep-al10b Yalep-al10b Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-04T10:19:20.138Z

Reserved: 2020-02-18T00:00:00.000Z

Link: CVE-2020-9247

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-07T13:15:11.123

Modified: 2024-11-21T05:40:15.980

Link: CVE-2020-9247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses