LiveActive security incident?Get immediate response
CVE Record

CVE-2020-36600: Out-of-bounds write vulnerability in the power consumption module.

Out-of-bounds write vulnerability in the power consumption module. Successful exploitation of this vulnerability may cause the system to restart.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

Affected Huawei EMUI and Magic UI versions contain a memory-handling flaw in a power-related component. Successful exploitation may restart the device, creating availability disruption. The supplied sources do not indicate data theft, privilege gain, or active exploitation.

Executive priority

Treat this as a targeted mobile availability risk, not a confirmed breach driver. Prioritize inventory and vendor updates for business-critical Huawei or Honor devices, especially where restarts would interrupt operations.

Technical view

CVE-2020-36600 is an out-of-bounds write in the power consumption module of Huawei EMUI and Magic UI. Sources list affected major versions but provide no CVSS, CWE, attack vector, prerequisites, or fixed build details. The documented impact is system restart.

Likely exposure

Exposure is limited to devices running Huawei EMUI 10.0.0, 10.1.0, 10.1.1, 11.0.0 or Magic UI 3.0.0, 3.1.0, 3.1.1, 4.0.0. Confirm actual device OS builds against Huawei guidance.

Exploitation context

The source bundle marks KEV as false, and no cited source states active exploitation. Public details are sparse; exploitation requirements and whether local, adjacent, or remote access is needed are not provided.

Researcher notes

Evidence is incomplete. The CVE describes the bug class and restart impact, but omits vector, privileges, user interaction, affected models, and patch identifiers. Avoid assuming exploitability beyond the stated out-of-bounds write and restart outcome.

Mitigation direction

  • Review Huawei's September 2022 security bulletin for affected and fixed build guidance.
  • Update affected Huawei EMUI or Magic UI devices using vendor-supported update channels.
  • Prioritize devices used for critical operations where unexpected restarts disrupt work.
  • Restrict use of unsupported affected devices until vendor guidance is confirmed.

Validation and detection

  • Inventory Huawei and Honor devices and record EMUI or Magic UI versions.
  • Compare observed versions with the affected versions listed for CVE-2020-36600.
  • Check Huawei support channels for fixed build availability for each device model.
  • Review device stability reports for unexplained restarts on affected versions.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-36600 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
HuaweiEMUI10.0.0, 10.1.0, 10.1.1, 11.0.0Listed
HuaweiMagic UI3.0.0, 3.1.0, 3.1.1, 4.0.0Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.