PT-2020-15136 · Huawei · Oxfords-An00A

Published

2020-03-20

·

Updated

2023-02-03

·

CVE-2020-1878

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Huawei smartphone OxfordS-AN00A versions earlier than 10.0.1.152D(C735E152R3P3) Huawei smartphone OxfordS-AN00A versions earlier than 10.0.1.160(C00E160R4P1)
Description The issue is related to improper authentication. When the device performs an operation, authentication to the target component is improper. This allows attackers to exploit the issue by loading a malicious application, leading to information leak.
Recommendations For versions earlier than 10.0.1.152D(C735E152R3P3), update to version 10.0.1.152D(C735E152R3P3) or later. For versions earlier than 10.0.1.160(C00E160R4P1), update to version 10.0.1.160(C00E160R4P1) or later.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2020-1878

Affected Products

Oxfords-An00A