Vulnerabilities
Vulnerable Software
Huawei:  >> Harmonyos  >> 2.1  Security Vulnerabilities
There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may cause the dialog box for confirming the pairing not to be displayed during Bluetooth pairing.
CVSS Score
4.3
EPSS Score
0.0
Published
2022-11-09
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-11-09
The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-11-09
The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
CVSS Score
9.8
EPSS Score
0.001
Published
2022-11-09
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically.
CVSS Score
5.3
EPSS Score
0.001
Published
2022-11-09
The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-11-09
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-11-09
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
CVSS Score
9.8
EPSS Score
0.002
Published
2022-11-09
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
CVSS Score
9.8
EPSS Score
0.002
Published
2022-11-09
The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.
CVSS Score
9.8
EPSS Score
0.002
Published
2022-11-09


Contact Us

Shodan ® - All rights reserved