CVE-2020-9247
Summary
| CVE | CVE-2020-9247 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-07 13:15:00 UTC |
| Updated | 2020-12-08 16:27:00 UTC |
| Description | There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which is passed from user that would cause buffer overflow. The attacker should trick the user into installing and running a malicious application with a high privilege, successful exploit may cause code execution. Affected product include Huawei HONOR 20 PRO, Mate 20, Mate 20 Pro, Mate 20 X, P30, P30 Pro, Hima-L29C, Laya-AL00EP, Princeton-AL10B, Tony-AL00B, Yale-L61A, Yale-TL00B and YaleP-AL10B. |
Risk And Classification
Problem Types: CWE-120
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Hima-l29c | - | All | All | All |
| Hardware | Huawei | Hima-l29c | - | All | All | All |
| Operating System | Huawei | Hima-l29c Firmware | All | All | All | All |
| Operating System | Huawei | Hima-l29c Firmware | All | All | All | All |
| Hardware | Huawei | Honor 20 Pro | - | All | All | All |
| Hardware | Huawei | Honor 20 Pro | - | All | All | All |
| Operating System | Huawei | Honor 20 Pro Firmware | All | All | All | All |
| Operating System | Huawei | Honor 20 Pro Firmware | All | All | All | All |
| Hardware | Huawei | Laya-al00ep | - | All | All | All |
| Hardware | Huawei | Laya-al00ep | - | All | All | All |
| Operating System | Huawei | Laya-al00ep Firmware | All | All | All | All |
| Operating System | Huawei | Laya-al00ep Firmware | All | All | All | All |
| Hardware | Huawei | Mate 20 | - | All | All | All |
| Hardware | Huawei | Mate 20 | - | All | All | All |
| Operating System | Huawei | Mate 20 Firmware | All | All | All | All |
| Operating System | Huawei | Mate 20 Firmware | All | All | All | All |
| Hardware | Huawei | Mate 20 Pro | - | All | All | All |
| Hardware | Huawei | Mate 20 Pro | - | All | All | All |
| Operating System | Huawei | Mate 20 Pro Firmware | All | All | All | All |
| Operating System | Huawei | Mate 20 Pro Firmware | All | All | All | All |
| Hardware | Huawei | Mate 20 X | - | All | All | All |
| Hardware | Huawei | Mate 20 X | - | All | All | All |
| Operating System | Huawei | Mate 20 X Firmware | All | All | All | All |
| Operating System | Huawei | Mate 20 X Firmware | All | All | All | All |
| Hardware | Huawei | P30 | - | All | All | All |
| Hardware | Huawei | P30 | - | All | All | All |
| Operating System | Huawei | P30 Firmware | All | All | All | All |
| Operating System | Huawei | P30 Firmware | 9.1.0.272\(c635e4r2p2\) | All | All | All |
| Operating System | Huawei | P30 Firmware | All | All | All | All |
| Operating System | Huawei | P30 Firmware | 9.1.0.272\(c635e4r2p2\) | All | All | All |
| Hardware | Huawei | P30 Pro | - | All | All | All |
| Hardware | Huawei | P30 Pro | - | All | All | All |
| Operating System | Huawei | P30 Pro Firmware | All | All | All | All |
| Operating System | Huawei | P30 Pro Firmware | All | All | All | All |
| Hardware | Huawei | Princeton-al10b | - | All | All | All |
| Hardware | Huawei | Princeton-al10b | - | All | All | All |
| Operating System | Huawei | Princeton-al10b Firmware | All | All | All | All |
| Operating System | Huawei | Princeton-al10b Firmware | All | All | All | All |
| Hardware | Huawei | Tony-al00b | - | All | All | All |
| Hardware | Huawei | Tony-al00b | - | All | All | All |
| Operating System | Huawei | Tony-al00b Firmware | All | All | All | All |
| Operating System | Huawei | Tony-al00b Firmware | All | All | All | All |
| Hardware | Huawei | Yale-l61a | - | All | All | All |
| Hardware | Huawei | Yale-l61a | - | All | All | All |
| Operating System | Huawei | Yale-l61a Firmware | All | All | All | All |
| Operating System | Huawei | Yale-l61a Firmware | All | All | All | All |
| Hardware | Huawei | Yale-tl00b | - | All | All | All |
| Hardware | Huawei | Yale-tl00b | - | All | All | All |
| Operating System | Huawei | Yale-tl00b Firmware | All | All | All | All |
| Operating System | Huawei | Yale-tl00b Firmware | All | All | All | All |
| Hardware | Huawei | Yalep-al10b | - | All | All | All |
| Hardware | Huawei | Yalep-al10b | - | All | All | All |
| Operating System | Huawei | Yalep-al10b Firmware | All | All | All | All |
| Operating System | Huawei | Yalep-al10b Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Buffer Overflow Vulnerability in Several Smartphones | MISC | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.