Vulnerabilities > Huawei > Mate 20 Firmware

DATE CVE VULNERABILITY TITLE RISK
2020-01-21 CVE-2020-1840 Improper Authentication vulnerability in Huawei Mate 20 Firmware
HUAWEI Mate 20 smart phones with versions earlier than 10.0.0.175(C00E70R3P8) have an insufficient authentication vulnerability.
local
low complexity
huawei CWE-287
3.6
2020-01-09 CVE-2020-1787 Improper Authentication vulnerability in Huawei Mate 20 Firmware 9.0.0.205(C00E205R2P1)/9.1.0.131(C00E131R3P1)
HUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability.
local
low complexity
huawei CWE-287
7.2
2019-12-13 CVE-2019-5251 Path Traversal vulnerability in Huawei products
There is a path traversal vulnerability in several Huawei smartphones.
network
huawei CWE-22
4.3
2019-11-29 CVE-2019-5227 Improper Input Validation vulnerability in Huawei products
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability.
network
huawei CWE-20
4.3
2019-11-29 CVE-2019-5225 Classic Buffer Overflow vulnerability in Huawei Mate 20 Firmware, P30 Firmware and P30 PRO Firmware
P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.135(C00E200R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R1P12) have a buffer overflow vulnerability on several , the system does not properly validate certain length parameter which an application transports to kernel.
network
huawei CWE-120
6.8
2019-11-29 CVE-2019-5226 Improper Input Validation vulnerability in Huawei products
P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions earlier than VOGUE-AL00A 9.1.0.193(C00E190R2P1), versions earlier than Hima-AL00B 9.1.0.135(C00E133R2P1) and HiSuite with versions earlier than HiSuite 9.1.0.305 have a version downgrade vulnerability.
network
huawei CWE-20
4.3
2019-08-14 CVE-2019-9506 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation.
4.8
2019-07-10 CVE-2019-5220 Incorrect Authorization vulnerability in Huawei products
There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones.
local
low complexity
huawei CWE-863
2.1
2018-12-04 CVE-2018-7956 Unspecified vulnerability in Huawei products
Huawei VIP App is a mobile app for Malaysia customers that purchased P20 Series, Nova 3/3i and Mate 20.
network
low complexity
huawei
5.0