CVE-2023-1692Incorrect Permission Assignment in Huawei Emui

Severity
7.5HIGHNVD
EPSS
0.1%
top 71.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 20

Description

The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

CVEListV5huawei/emui4 versions+3
NVDhuawei/emui4 versions+3
CVEListV5huawei/harmonyos5 versions+4
NVDhuawei/harmonyos5 versions+4

🔴Vulnerability Details

2
CVEList
CVE-2023-1692: The window management module lacks permission verification2023-05-20
GHSA
GHSA-j3r9-59j3-hq29: The window management module lacks permission verification2023-05-20

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Hard-coded password vulnerability could allow attacker to completely take over Lenovo Smart Clock2023-04-13
Talos
Vulnerability Spotlight: Hard-coded password vulnerability could allow attacker to completely take over Lenovo Smart Clock2023-04-13
CVE-2023-1692 — Incorrect Permission Assignment | cvebase