Update Package Verification Bypass in Huawei HarmonyOS Devices
CVE-2022-37008

7.5HIGH

Key Information:

Vendor
Huawei
Vendor
CVE Published:
10 August 2022

Summary

A vulnerability exists in the recovery module of Huawei HarmonyOS that allows attackers to bypass the verification process of update packages. This exploitation can lead to compromised system integrity and potentially destabilize the device's functionality. Users are strongly advised to keep their devices updated and monitor security bulletins for patched versions to mitigate this risk.

Affected Version(s)

EMUI 12.0.0

EMUI 11.0.1

EMUI 11.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.