Race Condition Vulnerability in MPTCP Module of HarmonyOS Devices
CVE-2022-39006

5.9MEDIUM

Key Information:

Vendor
Huawei
Vendor
CVE Published:
16 September 2022

Summary

The MPTCP (Multipath Transmission Control Protocol) module in HarmonyOS has a vulnerability that may allow a race condition to occur. If exploited, this vulnerability can lead to unintended device behavior, including potential restarts, impacting the usability and stability of affected devices. Users and administrators should stay informed about this issue and apply necessary updates to mitigate risks.

Affected Version(s)

EMUI 12.0.0

EMUI 11.0.1

EMUI 11.0.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.