Show plain JSON{"id": "CVE-2020-9073", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 2.1, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "LOW", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 2.4, "attackVector": "PHYSICAL", "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 1.4, "exploitabilityScore": 0.9}]}, "published": "2020-05-15T14:15:11.967", "references": [{"url": "https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200513-01-smartphone-en", "tags": ["Vendor Advisory"], "source": "psirt@huawei.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-287"}]}], "descriptions": [{"lang": "en", "value": "Huawei P20 smartphones with versions earlier than 10.0.0.156(C00E156R1P4) have an improper authentication vulnerability. The vulnerability is due to that when an user wants to do certain operation, the software insufficiently validate the user's identity. Attackers need to physically access the smartphone to exploit this vulnerability. Successful exploit could allow the attacker to bypass the limit of student mode function."}, {"lang": "es", "value": "Los tel\u00e9fonos inteligentes Huawei P20 con versiones anteriores a 10.0.0.156(C00E156R1P4), presentan una vulnerabilidad de autenticaci\u00f3n inapropiada. La vulnerabilidad es debido a que cuando un usuario quiere hacer una determinada operaci\u00f3n, el software no comprueba suficientemente la identidad del usuario. Los atacantes necesitan acceder f\u00edsicamente al tel\u00e9fono inteligente para explotar esta vulnerabilidad. Un explotaci\u00f3n con \u00e9xito podr\u00eda permitir al atacante omitir el l\u00edmite de la funci\u00f3n student mode."}], "lastModified": "2020-05-19T14:03:15.700", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:huawei:p20_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5CBA0F24-B073-4DEF-B8DF-4FE72940927C", "versionEndExcluding": "10.0.0.156\\(c00e156r1p4\\)"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:huawei:p20:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7492911B-4242-4947-9DED-9F48FC0875CD"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "psirt@huawei.com"}