CVE-2020-9249
CVE-2020-9249 is a medium-severity vulnerability in Huawei P30 Firmware with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-401.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v2: 3.3
- EPSS exploit prediction: 0% (25th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-401
- Affected product: Huawei P30 Firmware
- Published:
- Last modified:
Description
HUAWEI P30 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have a denial of service vulnerability. A module does not deal with mal-crafted messages and it leads to memory leak. Attackers can exploit this vulnerability to make the device denial of service.Affected product versions include: HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11).
Frequently asked questions
- What is CVE-2020-9249?
- HUAWEI P30 smartphones with versions earlier than 10.1.0.160(C00E160R2P11) have a denial of service vulnerability. A module does not deal with mal-crafted messages and it leads to memory leak. Attackers can exploit this vulnerability to make the device denial of service.Affected product versions include: HUAWEI P30 versions Versions earlier than 10.1.0.160(C00E160R2P11).
- How severe is CVE-2020-9249?
- CVE-2020-9249 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over an adjacent network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2020-9249 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (25th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-9249?
- CVE-2020-9249 affects Huawei P30 Firmware. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-9249?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2020-9249 published?
- CVE-2020-9249 was published on 2020-07-31 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:*
More vulnerabilities in Huawei P30 Firmware
- CVE-2020-0022 — High (CVSS 8.8): In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds…
- CVE-2019-9506 — High (CVSS 8.1): The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and…
- CVE-2020-9247 — High (CVSS 7.8): There is a buffer overflow vulnerability in several Huawei products. The system does not sufficiently validate certain…
- CVE-2020-9263 — High (CVSS 7.8): HUAWEI Mate 30 versions earlier than 10.1.0.150(C00E136R5P3) and HUAWEI P30 version earlier than…
- CVE-2020-1800 — High (CVSS 7.8): HUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access control…
- CVE-2020-1812 — High (CVSS 7.8): HUAWEI P30 smartphones with versions earlier than 10.0.0.173(C00E73R1P11) have an improper authentication…
All CVEs affecting Huawei P30 Firmware →
Other CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities
- CVE-2026-46289 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in…
- CVE-2025-39948 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: ice: fix Rx page leak on multi-buffer frames The…
- CVE-2025-21954 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netmem: prevent TX of unreadable skbs Currently…
- CVE-2024-57947 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map…
- CVE-2024-56779 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfs4_openowner leak when concurrent…
- CVE-2024-36911 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo…
Browse all CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities →