Identity Verification Vulnerability in Huawei ParamWatcher Module
CVE-2024-12602

6.2MEDIUM

Key Information:

Vendor
Huawei
Status
Vendor
CVE Published:
6 February 2025

Summary

The ParamWatcher module by Huawei contains an identity verification vulnerability that, if exploited, could compromise the confidentiality of services. This flaw may allow unauthorized access to sensitive information, making it critical for organizations to address this issue promptly to safeguard their systems.

Affected Version(s)

HarmonyOS 5.0.0

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.