CVE-2020-9250

Published Dec 20, 2024

Last updated 5 months ago

Overview

Description
There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful exploitation may impact the service. (Vulnerability ID: HWPSIRT-2019-12302) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9250.
Source
psirt@huawei.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
3.3
Impact score
1.4
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Severity
LOW

Weaknesses

psirt@huawei.com
CWE-287
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-522

Social media

Hype score
Not currently trending