Huawei smartphone OxfordS-AN00A with versions earlier than 10.0.1.152D(C735E152R3P3),versions earlier than 10.0.1.160(C00E160R4P1) have an improper authentication vulnerability. Authentication to target component is improper when device performs an operation. Attackers exploit this vulnerability to obtain some information by loading malicious application, leading to information leak.
References
Link | Resource |
---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200311-01-informationleak-en | Vendor Advisory |
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200415-02-dos-en | Not Applicable |
Information
Published : 2020-03-20 08:15
Updated : 2023-02-03 08:51
NVD link : CVE-2020-1878
Mitre link : CVE-2020-1878
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
huawei
- oxfords-an00a_firmware
- oxfords-an00a