CVE-2020-9235 describes an information disclosure vulnerability in various Huawei HONOR 20 PRO smartphone versions earlier than specified updates. A design error in a module, specifically a lack of input control (CWE-20), allows attackers to obtain sensitive information. Rated as Medium severity with a CVSS score of 5.5, this vulnerability has a local attack vector (AV:L) and low attack complexity (AC:L), requiring low privileges (PR:L) and no user interaction (UI:N). The primary impact is high confidentiality loss (C:H), with no integrity or availability impact. There is currently no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, indicating low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.1.0.230\(c432e9r5p1\)CPE matchmatch criteria | cpe:2.3:o:huawei:honor_20_pro_firmware:*:*:*:*:*:*:*:* | ||
< 10.1.0.231\(c10e3r3p2\)CPE matchmatch criteria | cpe:2.3:o:huawei:honor_20_pro_firmware:*:*:*:*:*:*:*:* | ||
< 10.1.0.231\(c185e3r5p1\)CPE matchmatch criteria | cpe:2.3:o:huawei:honor_20_pro_firmware:*:*:*:*:*:*:*:* | ||
< 10.1.0.231\(c636e3r3p1\)CPE matchmatch criteria | cpe:2.3:o:huawei:honor_20_pro_firmware:*:*:*:*:*:*:*:* | ||
< 10.1.0.212\(c432e10r3p4\)CPE matchmatch criteria | cpe:2.3:o:huawei:honor_view_20_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.