Input Parameter Verification Flaw in Widget Framework Module by Huawei
CVE-2024-56437
5.7MEDIUM
Summary
A vulnerability exists in the widget framework module of Huawei products due to unverified input parameters. This flaw can potentially lead to unauthorized access and impact the availability of the affected products. Proper validation of inputs is crucial to prevent exploitation in applications relying on this framework.
Affected Version(s)
HarmonyOS 5.0.0
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database