Input Parameter Validation Flaw in Huawei's 3D Engine Module
CVE-2024-56453

6.8MEDIUM

Key Information:

Vendor
Huawei
Status
Vendor
CVE Published:
8 January 2025

Summary

A vulnerability exists in Huawei's 3D Engine Module where input parameters are not properly validated during the loading of glTF models. This flaw could potentially lead to disruptions in service availability, allowing malicious actors to manipulate model loading processes. Ensuring rigorous input validation is essential to mitigate the risks associated with this vulnerability.

Affected Version(s)

HarmonyOS 5.0.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.