Arbitrary Write Vulnerability in Huawei Gallery Module
CVE-2024-57955

6.1MEDIUM

Key Information:

Vendor
Huawei
Status
Vendor
CVE Published:
6 February 2025

Summary

The Gallery module in Huawei's software has been found to possess an arbitrary write vulnerability. This flaw allows malicious actors to manipulate files or data within the system, potentially leading to unauthorized access and compromise of service confidentiality. Users are advised to monitor their systems and apply any available patches to mitigate risks associated with this vulnerability.

Affected Version(s)

HarmonyOS 5.0.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.