PT-2020-20546 · Huawei · Huawei Mate 20

Ding Yicong

·

Published

2020-07-27

·

Updated

2021-07-21

·

CVE-2020-9251

CVSS v3.1

2.4

Low

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R2P11) HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8)
Since both versions are essentially the same, with the difference being in the patch level (R2P11 vs R3P8), and given that R3P8 is a more specific and potentially later patch, we can consolidate this information into a single line for clarity and accuracy:
HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8)
Description The issue is related to an improper authorization vulnerability where the software does not properly restrict certain operations under specific scenarios. This can be exploited if the attacker configures the device in a certain way before the user enables the student mode function. Successful exploitation could allow the attacker to bypass the limitations imposed by the student mode function.
Recommendations For HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), update to version 10.1.0.160(C00E160R3P8) or later to resolve the issue. As a temporary workaround, consider restricting the use of the student mode function until a patch is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-9251

Affected Products

Huawei Mate 20