Input Parameter Verification Flaw in Widget Framework Module by Huawei
CVE-2024-56437

5.7MEDIUM

Key Information:

Vendor
Huawei
Status
Vendor
CVE Published:
8 January 2025

Summary

A vulnerability exists in the widget framework module of Huawei products due to unverified input parameters. This flaw can potentially lead to unauthorized access and impact the availability of the affected products. Proper validation of inputs is crucial to prevent exploitation in applications relying on this framework.

Affected Version(s)

HarmonyOS 5.0.0

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.