CVE-2020-9235:Input Validation Vulnerability in Huawei Smartphones Leading to Information Leak

splash
Back

Description Preview

Multiple Huawei smartphone models, including various HONOR 20 PRO versions, contain an information vulnerability due to improper input validation (CWE-20). A specific module in these devices lacks proper control of input, which could allow attackers to exploit this vulnerability to obtain sensitive information, resulting in an information leak. This affects numerous firmware versions released prior to various security updates.

Overview

This vulnerability (CVE-2020-9235) affects multiple Huawei smartphone models, particularly HONOR 20 PRO devices running firmware versions prior to specific security updates. The vulnerability stems from a design error in a module that fails to properly validate or control input data. By exploiting this vulnerability, attackers could potentially access information that should be restricted, leading to information disclosure. The vulnerability is classified as CWE-20 (Improper Input Validation), which occurs when software fails to validate input properly, allowing an attacker to craft the input in a form that is not expected by the rest of the application.

Remediation

Users should update their Huawei smartphones to the latest available firmware version. Specifically, the following minimum versions should be installed depending on your device model and region:

  • Version 10.1.0.230(C432E9R5P1) or later
  • Version 10.1.0.231(C10E3R3P2) or later
  • Version 10.1.0.231(C185E3R5P1) or later
  • Version 10.1.0.231(C636E3R3P1) or later
  • Version 10.1.0.212(C432E10R3P4) or later
  • Version 10.1.0.213(C636E3R4P3) or later
  • Version 10.1.0.214(C10E5R4P3) or later
  • Version 10.1.0.214(C185E3R3P3) or later
  • Version 10.1.0.212(C00E210R5P1) or later
  • Version 10.1.0.160(C00E160R2P11) or later
  • Version 10.1.0.160(C01E160R2P11) or later
  • Version 10.1.0.160(C00E160R8P12) or later
  • Version 10.1.0.225(C431E3R1P2) or later
  • Version 10.1.0.225(C432E3R1P2) or later

To update your device, go to Settings > System > Software update, or check for updates through Huawei's HiCare app.

References

  1. Huawei Security Advisory: https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200902-07-smartphone-en
  2. Common Weakness Enumeration (CWE-20): https://cwe.mitre.org/data/definitions/20.html
  3. MITRE CVE Entry: CVE-2020-9235

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Accommodation & Food Services
    Accommodation & Food Services
  2. Administrative, Support, Waste Management & Remediation Services
    Administrative, Support, Waste Management & Remediation Services
  3. Agriculture, Forestry Fishing & Hunting
    Agriculture, Forestry Fishing & Hunting
  4. Arts, Entertainment & Recreation
    Arts, Entertainment & Recreation
  5. Construction
    Construction
  6. Educational Services
    Educational Services
  7. Finance and Insurance
    Finance and Insurance
  8. Health Care & Social Assistance
    Health Care & Social Assistance
  9. Information
    Information
  10. Management of Companies & Enterprises
    Management of Companies & Enterprises
  11. Manufacturing
    Manufacturing
  12. Mining
    Mining
  13. Other Services (except Public Administration)
    Other Services (except Public Administration)
  14. Professional, Scientific, & Technical Services
    Professional, Scientific, & Technical Services
  15. Public Administration
    Public Administration
  16. Real Estate Rental & Leasing
    Real Estate Rental & Leasing
  17. Retail Trade
    Retail Trade
  18. Transportation & Warehousing
    Transportation & Warehousing
  19. Utilities
    Utilities
  20. Wholesale Trade
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background
Armis Vulnerability Intelligence Database