← Vulnerability feed

Vulnerability record · CVE-2020-1796 · published 20 March 2020

CVE-2020-1796: Huawei mate 20 firmware incorrect authorization vulnerability

Huawei · Mate 20 Firmware

There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successful exploit could allow a low privilege user to do certain operation which the user are supposed not to do.Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).

6.6 CVSS 3.1 Medium EPSS 0.20% · top 91.4% CWE-863 · Incorrect authorization
6.6CVSS 3.1 base score, v2 4.6
0.20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

There is an improper authorization vulnerability in several smartphones. The software incorrectly performs an authorization to certain user, successful exploit could allow a low privilege user to do certain operation which the user are supposed not to do.Affected product versions include:HUAWEI Mate 20 versions Versions earlier than 10.0.0.188(C00E74R3P8);HUAWEI Mate 30 Pro versions Versions earlier than 10.0.0.203(C00E202R7P2).

CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-1796 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-0022Google android vulnerabilityIn reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to …EPSS 6.1%8.1CVE-2019-9506Google android broken cryptographic algorithm vulnerabilityThe Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker fr…EPSS 2.7%8.0CVE-2020-9113Huawei mate 20 firmware classic buffer overflow vulnerabilityHUAWEI Mate 20 versions earlier than 10.0.0.188(C00E74R3P8) have a buffer overflow vulnerability in the Bluetooth module. Due to insufficient input v…EPSS 0.45%7.8CVE-2020-9247Huawei honor 20 pro firmware classic buffer overflow vulnerabilityThere is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain configuration parameter which …EPSS 0.83%7.8CVE-2019-5225Huawei p30 firmware classic buffer overflow vulnerabilityP30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions earlier than Hima-AL00B 9.1.0.1…EPSS 0.83%6.8CVE-2020-9081Huawei mate 20 firmware improper authorization vulnerabilityThere is an improper authorization vulnerability in some Huawei smartphones. An attacker could perform a series of operation in specific mode to expl…EPSS 0.20%6.8CVE-2020-9244Huawei mate 20 firmware vulnerabilityHUAWEI Mate 20 versions Versions earlier than 10.1.0.160(C00E160R3P8);HUAWEI Mate 20 Pro versions Versions earlier than 10.1.0.270(C431E7R1P5),Versio…EPSS 0.23%6.6CVE-2020-1787Huawei mate 20 firmware improper authentication vulnerabilityHUAWEI Mate 20 smartphones versions earlier than 9.1.0.139(C00E133R3P1) have an improper authentication vulnerability. The system has a logic error u…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2020-1796), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.