Evidence dossier

CVE-2020-0069

In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions.

Exploited in the wild (CISA KEV since Nov 3, 2021). NVD reports CVSS 3.1 7.8. EPSS estimates 1.4% exploit likelihood as of Aug 27, 2026.

71.071.6Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754

State
PUBLISHED
Published
Mar 10, 2020
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    google_android

    Record text: In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754

    Inspect raw assertion
    Field
    container
    Value
    In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 1.37% probability · 69.91th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.013700000000; percentile 0.699110000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Nov 3, 2021 · first observed Jul 19, 2026

Exploit likelihood1.37%

FIRST EPSS · score date Aug 27, 2026 · 69.9th percentile · first observed Aug 27, 2026

SeverityCVSS 7.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
google_androidOriginal assertion
Record text

In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754

Inspect raw assertion
Field
container
Value
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

1.37% probability · 69.91th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.013700000000; percentile 0.699110000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
77Underlying assertions
57Canonical products
39Target assertions
38Constraint assertions

Grouped from 77 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

58 scope groups

google_android · source assertedn/aAndroidDirect source scope
Affected: Android kernel
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "Android kernel"}]
NVD CPE · OPERATING SYSTEMgoogleandroidVulnerable target · 1 assertions
Version not applicableCanonical identity product-92706ad297e0bcadcd6adc374dd80eb27012c37cd92e19cf49650461139673ecLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f8b9fec8-73b6-43b8-b24e-1f7c20d91d26
NVD CPE · HARDWAREhuaweiberkeley-l09Environmental constraint · 1 assertions
Version not applicableCanonical identity product-43a5fc8a147f5baa7f4d960a4ddab4a2ad8299443d3ec985c46f4a2b314456f0Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:huawei:berkeley-l09:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    db51593f-70ae-47f6-afe5-02693181e599
NVD CPE · OPERATING SYSTEMhuaweiberkeley-l09_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 10.0.0.177\(c10e3r1p4\))Canonical identity product-8fba24c95a4089c4b915b020242510ebabf6da30c6e7003a17aa3032d2c175bfLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:huawei:berkeley-l09_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 10.0.0.177\(c10e3r1p4\)
    Match ID
    bcefda14-c332-4604-85e5-332231b8853b
NVD CPE · HARDWAREhuaweicolumbia-al10bEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-b68319823de3cffe94382c993f5810307824da2f949fd1c6bb077a422b19891aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:huawei:columbia-al10b:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2f63ca2f-45b8-4dd3-81ae-8359929ae50b
NVD CPE · OPERATING SYSTEMhuaweicolumbia-al10b_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 10.0.0.178\(c00e178r1p4\))Canonical identity product-71866f0b7d8cfcf3e83d70be52f4060fd9694106acf8d65a5b44b0830d8b598dLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:huawei:columbia-al10b_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 10.0.0.178\(c00e178r1p4\)
    Match ID
    046c3c00-63a5-4ca9-9bfa-dedf7d3a1d90
NVD CPE · HARDWAREhuaweicolumbia-l29dEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-cd2f3e5049c1755a7964e3e71500c20becd7df44b7f3936e122a4164a89ccfbdLinked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:huawei:columbia-l29d:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    07042814-6b3a-4d7c-a776-02da9ac9b8dc
  2. cpe:2.3:h:huawei:columbia-l29d:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    29 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    07042814-6b3a-4d7c-a776-02da9ac9b8dc
NVD CPE · OPERATING SYSTEMhuaweicolumbia-l29d_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (< 10.0.0.177\(c10e4r1p4\)); Any version (unconstrained) (< 10.0.0.177\(c432e3r1p4\))Canonical identity product-fbbe4baa5d142e31063a330f791b2ec67725284e08e389d8036cff58470df153Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:huawei:columbia-l29d_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    29 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 10.0.0.177\(c432e3r1p4\)
    Match ID
    ecbcd3c2-25b7-431d-8277-e25616008891
  2. cpe:2.3:o:huawei:columbia-l29d_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 10.0.0.177\(c10e4r1p4\)
    Match ID
    3135bbc7-2a18-47e9-9041-16077b1102a2
NVD CPE · HARDWAREhuaweicolumbia-tl00bEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-e2b457ea27fb69bc381c734e920d451d6ad11d37bfc54b2d441377a1649d6b3fLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:huawei:columbia-tl00b:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    02334509-2493-419f-8ff5-e1f1076fb930
NVD CPE · OPERATING SYSTEMhuaweicolumbia-tl00b_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 10.0.0.178\(c01e178r1p4\))Canonical identity product-bb31f371c6dabf7da482fa0f0229c207d1994e7c37753c46600145ca3a412c9bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:huawei:columbia-tl00b_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 10.0.0.178\(c01e178r1p4\)
    Match ID
    42e8c828-0c05-4cd7-bc72-98ac05c6dde5
NVD CPE · HARDWAREhuaweicolumbia-tl00dEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-af83512d681a6ad8a6dd8eb134fb67efc60b68d3c60ac652c9f059ccaaf99cdeLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:huawei:columbia-tl00d:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    5 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6be1bb06-0403-4f46-af76-dad85d538907
NVD CPE · OPERATING SYSTEMhuaweicolumbia-tl00d_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 10.0.0.178\(c01e178r1p4\))Canonical identity product-b7e7acca77a054680662e047ee3ecf3470f7d901bd7e0943bb665c50b38524f6Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:huawei:columbia-tl00d_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 10.0.0.178\(c01e178r1p4\)
    Match ID
    142a8425-13e2-4215-80b6-80921ba7b3c1
NVD CPE · HARDWAREhuaweicornell-al00aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-5b8270ef6548d4ff15bf5b9feb60dc331e03270c0d6dd47c30090ca14e0f62b8Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:huawei:cornell-al00a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ab5193b7-6f3f-4249-bb74-62480893cab2
NVD CPE · OPERATING SYSTEMhuaweicornell-al00a_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 9.1.0.340\(c00e333r1p1t8\))Canonical identity product-6ad56cb0419f82eca984a9f19224123e526d491f5fc38bcd688b0ed4aa5d33e8Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:huawei:cornell-al00a_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 9.1.0.340\(c00e333r1p1t8\)
    Match ID
    5bd55a2a-8a54-4e48-b352-f7042bbf2c3f
NVD CPE · HARDWAREhuaweicornell-tl10bEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-aa53593ffbf9469aadd774ea98e5e5816b1d23240d28f3745f59d2402237bd36Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:huawei:cornell-tl10b:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    7 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    73f60e9a-0acb-4e44-adfb-771c695fcf08
NVD CPE · OPERATING SYSTEMhuaweicornell-tl10b_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 9.1.0.340\(c01e333r1p1t8\))Canonical identity product-e1eeb203348860d332375e7c8866471f5bd7bee048949a3aba6eb0287ec2e788Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:huawei:cornell-tl10b_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 9.1.0.340\(c01e333r1p1t8\)
    Match ID
    f8df2be8-65fb-43df-9fcd-e79c7df0bb16
NVD CPE · HARDWAREhuaweidura-al00aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-dce8799ee13cc56cf37f4146f45aaede5494f533cd9ba9e827335892482736cbLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:huawei:dura-al00a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    8 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    dc591fa6-55e1-4628-ae43-cd1e2a4980e9
NVD CPE · OPERATING SYSTEMhuaweidura-al00a_firmwareVulnerable target · 1 assertions
Any version (unconstrained) (< 1.0.0.190\(c00\))Canonical identity product-efa688329eeb86536ca88aba31ce4569be386dcaf703ed4e67db0e7cad694544Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:huawei:dura-al00a_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 1.0.0.190\(c00\)
    Match ID
    e79c71b2-0344-4afa-8aa5-560de03af9a4
NVD CPE · HARDWAREhuaweihonor_20_proEnvironmental constraint · 2 assertions
Version not applicableCanonical identity product-fd8b2b889c78da11d043febbbf41079fbe3c70e6668108ed538dfdf54fa97a62Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:huawei:honor_20_pro:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    30 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9e2bca7e-e555-45d1-807a-f53682b0c383
  2. cpe:2.3:h:huawei:honor_20_pro:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    9 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9e2bca7e-e555-45d1-807a-f53682b0c383
NVD CPE · OPERATING SYSTEMhuaweihonor_20_pro_firmwareVulnerable target · 2 assertions
Any version (unconstrained) (< 10.0.0.194\(c636e3r3p1\)); Any version (unconstrained) (< 10.0.0.202\(c10e3r3p2\))Canonical identity product-4bb76166ff373f7b2f714c10f7277adfea9fcf796bdd97e19c7362c63277c478Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:huawei:honor_20_pro_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 10.0.0.194\(c636e3r3p1\)
    Match ID
    15e9683f-8037-418c-90ab-7abdb6be13bd
  2. cpe:2.3:o:huawei:honor_20_pro_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    30 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 10.0.0.202\(c10e3r3p2\)
    Match ID
    59a1e3c0-5364-4c4d-bb27-69941aae68c0
NVD CPE · HARDWAREhuaweihonor_8aEnvironmental constraint · 4 assertions
Version not applicableCanonical identity product-8a95203f25bdcbe2d233cc0a5f94eb35487c0ce541c68952d7f6fcbf5d8a3abfLinked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:huawei:honor_8a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    36 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b2e19c33-f393-4e0c-9aa7-461af50edf7f
  2. cpe:2.3:h:huawei:honor_8a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    34 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b2e19c33-f393-4e0c-9aa7-461af50edf7f
  3. cpe:2.3:h:huawei:honor_8a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    35 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b2e19c33-f393-4e0c-9aa7-461af50edf7f
  4. cpe:2.3:h:huawei:honor_8a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    13 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b2e19c33-f393-4e0c-9aa7-461af50edf7f
NVD CPE · OPERATING SYSTEMhuaweihonor_8a_firmwareVulnerable target · 4 assertions
Any version (unconstrained) (< 9.1.0.291\(c185e3r4p1\)); Any version (unconstrained) (< 9.1.0.291\(c432e5r2p1\)); Any version (unconstrained) (< 9.1.0.291\(c636e4r4p1\)); Any version (unconstrained) (< 9.1.0.297\(c605e4r4p2\))Canonical identity product-7c79a490599f05750c01a86dff48e174d0865b65b2938a993d4e4a308145440eLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:huawei:honor_8a_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    36 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 9.1.0.297\(c605e4r4p2\)
    Match ID
    e1d1a153-274b-40a2-b9a8-f5e8b83258a1
  2. cpe:2.3:o:huawei:honor_8a_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 9.1.0.291\(c185e3r4p1\)
    Match ID
    2128bde5-ae3b-427e-8a25-f3065850206a
  3. cpe:2.3:o:huawei:honor_8a_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    35 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 9.1.0.291\(c636e4r4p1\)
    Match ID
    4a71a7a6-2220-45f0-b9e0-560632c36ee2
  4. cpe:2.3:o:huawei:honor_8a_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    34 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 9.1.0.291\(c432e5r2p1\)
    Match ID
    c2224974-8dcd-410a-a072-2d52b26bb56d
NVD CPE · HARDWAREhuaweihonor_view_20Environmental constraint · 3 assertions
Version not applicableCanonical identity product-188f96ef6c3459f2d201e318aa7333a8478cf220a7e007e284503c8400c04ef8Linked exact
Scope constrained
Inspect raw assertions
  1. cpe:2.3:h:huawei:honor_view_20:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    14 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6a55cf4f-8e86-419c-845b-ce60070620a3
  2. cpe:2.3:h:huawei:honor_view_20:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    37 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6a55cf4f-8e86-419c-845b-ce60070620a3
  3. cpe:2.3:h:huawei:honor_view_20:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    38 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6a55cf4f-8e86-419c-845b-ce60070620a3
NVD CPE · OPERATING SYSTEMhuaweihonor_view_20_firmwareVulnerable target · 3 assertions
Any version (unconstrained) (< 10.0.0.198\(c432e10r3p4\)); Any version (unconstrained) (< 10.0.0.200\(c185e3r3p3\)); Any version (unconstrained) (< 10.0.0.201\(c10e5r4p3\))Canonical identity product-1556630f0e41a0adc585db34b92da41368a14916b49becfeab6d366ab56ed1a8Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:huawei:honor_view_20_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    37 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 10.0.0.200\(c185e3r3p3\)
    Match ID
    511131df-79c4-41a5-a0d3-015a832b2c35
  2. cpe:2.3:o:huawei:honor_view_20_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    14 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 10.0.0.198\(c432e10r3p4\)
    Match ID
    43bba181-3dda-4be0-a21e-fcbe2fb39baa
  3. cpe:2.3:o:huawei:honor_view_20_firmware:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    38 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 10.0.0.201\(c10e5r4p3\)
    Match ID
    24dc8c7e-c586-4b6c-99a9-808202a7bd55
NVD CPE · HARDWAREhuaweijakarta-al00aEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-64a2f35eac01a1d6f159ba5f326218d8cdb34c84628637d7c96f8acf96787c37Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:huawei:jakarta-al00a:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    15 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    44e124fe-9f3e-4a89-9dfb-2acef751ba82

Affected-product evidence

Accepted scope and product mapping

29 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-036b8b79a72ff32593959cd82cd3530b1444220a5daf3c356a0fc893043c8331

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3010fe72-00c4-42df-bf4f-5dcbea1d9738
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-11d858423a67d86201e8c01580720bb9c1d150deda130602c3bd624caff7291c

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b16631c7-b3ed-4dc6-a4ff-5eb194fe3fd6
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-1556630f0e41a0adc585db34b92da41368a14916b49becfeab6d366ab56ed1a8

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
060fb85c-c734-4aa4-9e7d-dcdaf35c9ec182fe7c05-4814-4973-9523-676e82e440b890fe6e1f-b114-4b87-8c46-dbf9a3d1c954
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-181f35c60f38ce0cdc988a93b77b637225e62d76a655374ae69105b9aa835638

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ff641b82-79c2-4f27-9aee-44f0935db12b
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-22e899b744ac172e9e3b454493cccb453ec32080e77c87820eb55222ea3eadc1

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7260927d-ad43-44c9-9df5-562b894e8888
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-36f20469076308eea3532f5c4cac452991e125bfee0e6a58b4b033d6ffd95949

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
865f7294-1879-46fe-ad30-4ad26059fa3a
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-3a8c78a481a986a02128749681926491b1d1283e34ea11219c1f6fecdfeff36f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b59413fc-caf7-4399-9e94-c49191d1dce0
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-46dd7763e0e9de63860158b2bdd0fe1d9e9498a3bbc4b2e8a50279ba84e25b75

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
887d3147-29aa-48eb-a3aa-9f1633844ebc
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-4bb76166ff373f7b2f714c10f7277adfea9fcf796bdd97e19c7362c63277c478

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
19d65a94-9b2d-4b6c-9223-6d9655a31f1155c705d9-9ffb-4333-9212-ec5e84519d46
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-4c952d4939dd4ed2c1abf8886ae306c42902dab7b3e5c95a0744a0569b689619

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e7408059-25fe-425d-9181-df2414ef74eb
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-596c4496bc7d71af373738f15556c34d375356ed7c869e02420e41dd88491cdc

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c9fdb0bd-9531-46a1-89fc-9388274d628c
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-6ad56cb0419f82eca984a9f19224123e526d491f5fc38bcd688b0ed4aa5d33e8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0a42aa1e-50bd-437f-9c37-85d2fd11905c
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-71866f0b7d8cfcf3e83d70be52f4060fd9694106acf8d65a5b44b0830d8b598d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e26c02ae-35d5-4c54-964f-c3414e65eece
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-7c79a490599f05750c01a86dff48e174d0865b65b2938a993d4e4a308145440e

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
353e4302-ed08-418d-baf0-3c03bbb0357fa7d8ec37-698a-4088-a840-a849ffbaf015cb4c718c-d85d-4c33-ae1a-9fd0d253b4dfea83f0dd-943c-49c2-a418-d15e1af9a87a
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-8fba24c95a4089c4b915b020242510ebabf6da30c6e7003a17aa3032d2c175bf

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b032e531-df73-4f5b-b12a-564888a665a9
Mapping establishedEvidence supported

vendor-88869ec57256fdf5d0b9ffd6f3d141ad371acdd6f81405ddb6c5e9e45b10869c · product-92706ad297e0bcadcd6adc374dd80eb27012c37cd92e19cf49650461139673ec

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1550ae92-a0f5-4158-bcc2-2df6d1deb249
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-9c729a940dff71d1d17748f91ee1965a62cab82ce63dd9972c6d3a6432d5bb99

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
01272b51-9907-4906-9e39-dcbf3e8925af3a977d20-64dc-40f7-ab1f-53f5434c85bd78e3ce85-8868-43fe-a13e-f547ee71ec55ec59c8a3-304e-4a87-80a9-e6030a972d7d
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-b1036ffa86716fb83161418bd99c88261ff27941fdccb2c4babac17a2414ac68

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4bde8643-8047-415e-a263-db04beb2a373
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-b7e7acca77a054680662e047ee3ecf3470f7d901bd7e0943bb665c50b38524f6

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
18abe2bb-cee7-4a07-9d97-4b47c756db50
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-bb31f371c6dabf7da482fa0f0229c207d1994e7c37753c46600145ca3a412c9b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
aff83357-d250-4a04-9f92-05d417a99315
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-c23e02e3f9bd025553ecca7e065444a9def30b09d184ae92a452e819a4aaece7

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
eaa59803-057a-4617-bab4-8950239d852b
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-d165fc303e6617dfa1ffadc2e3eb7a45710c553889a3532683ac771574ab85ce

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6c6ae228-29c5-4ed8-bc62-3419051ff9d6
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-e1eeb203348860d332375e7c8866471f5bd7bee048949a3aba6eb0287ec2e788

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2658459c-fb2a-4971-8934-744d227789b8
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-e93bb1e919573eb8330568bbd22ceaa202c4d653f92ae706039d43d9ddc56669

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
28fca6dc-b7dd-46c5-a504-83fc94efc584
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-e964da1403be76be1048e477dbc6c1f0fc9cdc8b4a46ac0daf4b3b0762455523

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
74a25cb3-1c07-4dbb-9150-1f813ec91864
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-eb38cc85ce78124bc6b5b36a35bcacf098e345347c6307d938a2e4b672d08f10

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
cea4ad9f-3b01-4ebf-9598-929ab01faadc
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-eb4f48b95c77b71d7140a6efca3033088eefc8d74449cbec5de3401cab0cab7d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
83a29645-818c-4798-8e08-80a534f6cb06
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-efa688329eeb86536ca88aba31ce4569be386dcaf703ed4e67db0e7cad694544

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
008dd3ae-a542-4cfc-a357-3c014b765363
Mapping establishedEvidence supported

vendor-c01c4c4ca8e6e5b6483f04a2e0d209e5e6454c57578fad18b390c321d2cfd35d · product-fbbe4baa5d142e31063a330f791b2ec67725284e08e389d8036cff58470df153

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
11026114-4fe1-473c-8008-04a061196f207ed73aaf-4896-41ef-94ce-a69c211c41c0
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a20fc7d4-851e-4f15-bd3b-dc3774a0a518

Assessments

CVSS by origin

7.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.2
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:L/AC:L/Au:N/C:C/I:C/A:C
7.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

7.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
7.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.