SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-9119

There is a privilege escalation vulnerability on some Huawei smart phones due to design defects.

MEDIUM 6.2EPSS 0.22%

Does this matter?

Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.

Description

There is a privilege escalation vulnerability on some Huawei smart phones due to design defects. The attacker needs to physically contact the mobile phone and obtain higher privileges, and execute relevant commands, resulting in the user's privilege promotion.

CVSS 3.1
6.2 MEDIUMCVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.22% probability · 13th percentile
CISA KEV
Not listed
Affected
huawei/mate 10 firmware · huawei/mate 30 firmware · huawei/mate 30 pro firmware · huawei/p40 firmware · huawei/p40 pro firmware
Source
psirt@huawei.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.