Taurus-AL00A version 10.0.0.1(C00E1R1P1) has an out-of-bounds read vulnerability in XFRM module. An authenticated, local attacker may perform a specific operation to exploit this vulnerability. Due to insufficient validation of the parameters, which may be exploited to cause information leak.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200930-02-smartphone-en | vendor advisory |