CVE-2020-9250

There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to insufficient verification, successful exploitation may impact the service. (Vulnerability ID: HWPSIRT-2019-12302) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9250.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:mate_20_pro_firmware:10.1.0.160\(c00e160r3p8\):*:*:*:*:*:*:*
cpe:2.3:h:huawei:mate_20_pro:-:*:*:*:*:*:*:*

History

11 Jul 2025, 14:33

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200729-01-smartphone-en - () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200729-01-smartphone-en - Broken Link, Vendor Advisory
First Time Huawei
Huawei mate 20 Pro Firmware
Huawei mate 20 Pro
CPE cpe:2.3:h:huawei:mate_20_pro:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:mate_20_pro_firmware:10.1.0.160\(c00e160r3p8\):*:*:*:*:*:*:*
Summary
  • (es) Existe una vulnerabilidad de autenticación insuficiente en algunos teléfonos inteligentes Huawei. Un atacante local no autenticado puede manipular un paquete de software para explotar esta vulnerabilidad. Debido a una verificación insuficiente, una explotación exitosa puede afectar el servicio. (Identificador de vulnerabilidad: HWPSIRT-2019-12302) A esta vulnerabilidad se le ha asignado un identificador de vulnerabilidades y exposiciones comunes (CVE): CVE-2020-9250.

20 Dec 2024, 18:15

Type Values Removed Values Added
CWE CWE-522

20 Dec 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-20 02:15

Updated : 2025-07-11 14:33


NVD link : CVE-2020-9250

Mitre link : CVE-2020-9250

CVE.ORG link : CVE-2020-9250


JSON object : View

Products Affected

huawei

  • mate_20_pro_firmware
  • mate_20_pro
CWE
CWE-287

Improper Authentication

CWE-522

Insufficiently Protected Credentials