CVE-2022-46327Improper Privilege Management in Huawei Harmonyos

Severity
9.8CRITICALNVD
EPSS
0.2%
top 57.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 20

Description

Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDhuawei/harmonyos< 2.0
CVEListV5huawei/emui12.0.0
NVDhuawei/emui12.0.0
CVEListV5huawei/harmonyos2.0

Patches

🔴Vulnerability Details

2
CVEList
CVE-2022-46327: Some smartphones have configuration issues2022-12-20
GHSA
GHSA-3f9h-xcq9-8jp9: Some smartphones have configuration issues2022-12-20
CVE-2022-46327 — Improper Privilege Management | cvebase