CVE-2020-1788
Published Jan 21, 2020
Last updated 5 years ago
Overview
- Description
- Honor V30 smartphones with versions earlier than 10.0.1.135(C00E130R4P1) have an improper authentication vulnerability. Certain applications do not properly validate the identity of another application who would call its interface. An attacker could trick the user into installing a malicious application. Successful exploit could allow unauthorized actions leading to information disclosure.
- Source
- psirt@huawei.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-287
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:huawei:honor_v30_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DC7FFDFA-2349-40EA-8DBD-F308CE72F005", "versionEndExcluding": "10.0.1.135\\(c00e130r4p1\\)" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:huawei:honor_v30:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A90E11A8-FDDC-4F27-BA4F-52E158FAD83C" } ], "operator": "OR" } ], "operator": "AND" } ]