Bypass Flaw in Settings Application of HarmonyOS by Huawei
CVE-2022-37004

7.5HIGH

Key Information:

Vendor
Huawei
Vendor
CVE Published:
10 August 2022

Summary

The Settings application of HarmonyOS contains a bypass vulnerability that compromises the out-of-box experience (OOBE). Exploiting this flaw could potentially disrupt the availability of the impacted devices, leading to an impaired user experience. Users are encouraged to update their systems to mitigate risks associated with this vulnerability.

Affected Version(s)

EMUI 12.0.0

EMUI 11.0.1

EMUI 11.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.