CVE-2020-1808
Summary
| CVE | CVE-2020-1808 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-05-15 14:15:00 UTC |
| Updated | 2020-07-27 13:15:00 UTC |
| Description | Honor 20;HONOR 20 PRO;Honor Magic2;HUAWEI Mate 20 X;HUAWEI P30;HUAWEI P30 Pro;Honor View 20 smartphones with versions earlier than 10.0.0.187(C00E60R4P11); versions earlier than 10.0.0.187(C00E60R4P11); versions earlier than 10.0.0.176(C00E60R2P11);9.1.0.135(C00E133R2P1); versions earlier than 10.1.0.123(C431E22R3P5), versions earlier than 10.1.0.126(C636E5R3P4), versions earlier than 10.1.0.160(C00E160R2P11); versions earlier than 10.1.0.126(C185E8R5P1), versions earlier than 10.1.0.126(C636E9R2P4), versions earlier than 10.1.0.160(C00E160R2P8); versions earlier than 10.0.0.179(C636E3R4P3), versions earlier than 10.0.0.180(C185E3R3P3), versions earlier than 10.0.0.180(C432E10R3P4), versions earlier than 10.0.0.181(C675E5R1P2) have an out of bound read vulnerability. The software reads data past the end of the intended buffer. The attacker tricks the user into installing a crafted application, successful exploit may cause information disclosure or service abnormal. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Honor 20 | - | All | All | All |
| Hardware | Huawei | Honor 20 | - | All | All | All |
| Operating System | Huawei | Honor 20 Firmware | All | All | All | All |
| Operating System | Huawei | Honor 20 Firmware | All | All | All | All |
| Hardware | Huawei | Honor 20 Pro | - | All | All | All |
| Hardware | Huawei | Honor 20 Pro | - | All | All | All |
| Operating System | Huawei | Honor 20 Pro Firmware | All | All | All | All |
| Operating System | Huawei | Honor 20 Pro Firmware | All | All | All | All |
| Hardware | Huawei | Honor Magic2 | - | All | All | All |
| Hardware | Huawei | Honor Magic2 | - | All | All | All |
| Operating System | Huawei | Honor Magic2 Firmware | All | All | All | All |
| Operating System | Huawei | Honor Magic2 Firmware | All | All | All | All |
| Hardware | Huawei | Honor View 20 | - | All | All | All |
| Hardware | Huawei | Honor View 20 | - | All | All | All |
| Operating System | Huawei | Honor View 20 Firmware | All | All | All | All |
| Operating System | Huawei | Honor View 20 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Out of Bounds Read Vulnerability in Several Smartphones | MISC | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.