Identity Authentication Bypass in Huawei HiLink AI Life Product
CVE-2022-48470

4MEDIUM

Key Information:

Vendor
Huawei
Vendor
CVE Published:
28 December 2024

Summary

The Huawei HiLink AI Life product is affected by a significant identity authentication bypass vulnerability. This flaw enables attackers to potentially gain unauthorized access to restricted functions, leading to severe security implications for users and their data. Exploitation of this vulnerability can compromise the integrity of the system and the privacy of the users, urging the necessity for timely security measures. Users are advised to apply all relevant updates and patches to mitigate the risks associated with this vulnerability. For more information, refer to the security advisory provided by Huawei.

Affected Version(s)

HarmonyOS AILife Solution 6.0 HiLink AI Life 12.0.2.305

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.