Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C00E160R4P1) have an improper authentication vulnerability. Authentication to target component is improper when device performs an operation. Attackers exploit this vulnerability to obtain some information by loading malicious application, leading to information leak.
References
Link | Resource |
---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200415-02-dos-en | Not Applicable |
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200311-01-informationleak-en | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2020-03-20 15:15
Updated : 2023-02-03 16:51
NVD link : CVE-2020-1878
Mitre link : CVE-2020-1878
CVE.ORG link : CVE-2020-1878
JSON object : View
Products Affected
huawei
- oxfords-an00a
- oxfords-an00a_firmware
CWE
CWE-287
Improper Authentication