ZeroHour

CVE-2020-1786

CVSS 3.1
4.6 medium
EPSS
<1%p16
Published
()
Modified
Description

HUAWEI Mate 20 Pro smartphones versions earlier than 10.0.0.175(C00E69R3P8) have an improper authentication vulnerability. The software does not sufficiently validate the name of apk file in a special condition which could allow an attacker to forge a crafted application as a normal one. Successful exploit could allow the attacker to bypass digital balance function.

Vendors
huawei
Products
mate 20 pro firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.