CVE-2020-1878

Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C00E160R4P1) have an improper authentication vulnerability. Authentication to target component is improper when device performs an operation. Attackers exploit this vulnerability to obtain some information by loading malicious application, leading to information leak.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:oxfords-an00a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:oxfords-an00a:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:huawei:oxfords-an00a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:oxfords-an00a:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:11

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200415-02-dos-en - Not Applicable () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200415-02-dos-en - Not Applicable
References () https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200311-01-informationleak-en - Vendor Advisory () https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200311-01-informationleak-en - Vendor Advisory

Information

Published : 2020-03-20 15:15

Updated : 2024-11-21 05:11


NVD link : CVE-2020-1878

Mitre link : CVE-2020-1878

CVE.ORG link : CVE-2020-1878


JSON object : View

Products Affected

huawei

  • oxfords-an00a_firmware
  • oxfords-an00a
CWE
CWE-287

Improper Authentication