CVE-2023-1692
published 2023-05-20CVE-2023-1692: The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.38%
29.8th percentile
The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | emui | — | — |
| huawei | emui | — | — |
| huawei | emui | — | — |
| huawei | emui | — | — |
| huawei | harmonyos | — | — |
| huawei | harmonyos | — | — |
| huawei | harmonyos | — | — |
| huawei | harmonyos | — | — |
| huawei | harmonyos | — | — |
| huawei | harmonyos | — | — |
| huawei | harmonyos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Hard-coded password vulnerability could allow attacker to completely take over Lenovo Smart Clock
blogs_talos·2023-04-13·CVSS 8.8
CVE-2023-0896 [HIGH] Vulnerability Spotlight: Hard-coded password vulnerability could allow attacker to completely take over Lenovo Smart Clock
## Vulnerability Spotlight: Hard-coded password vulnerability could allow attacker to completely take over Lenovo Smart Clock
Kelly Leuschner and Thorsten Rosendahl discovered this vulnerability.
Cisco Talos researchers recently discovered a vulnerability in the Lenovo Smart Clock Essential that could allow an attacker to completely take over the device if they have access to the network the clock is connected to.
TALOS-2023-1692 (CVE-2023-0896) exists because the smart clock does not change its hardcoded credentials once it's set up and connected to the network. Therefore, an attacker could use a specially crafted command line argument to gain full control of the device using SSH or telnet if they already have network access.
Talos also alerted Lenovo that the clock’s hardcoded root p
Talos
Vulnerability Spotlight: Hard-coded password vulnerability could allow attacker to completely take over Lenovo Smart Clock
blogs_talos·2023-04-13·CVSS 8.8
CVE-2023-0896 [HIGH] Vulnerability Spotlight: Hard-coded password vulnerability could allow attacker to completely take over Lenovo Smart Clock
Kelly Leuschner and Thorsten Rosendahl discovered this vulnerability.
Cisco Talos researchers recently discovered a vulnerability in the Lenovo Smart Clock Essential that could allow an attacker to completely take over the device if they have access to the network the clock is connected to.
TALOS-2023-1692 (CVE-2023-0896) exists because the smart clock does not change its hardcoded credentials once it's set up and connected to the network. Therefore, an attacker could use a specially crafted command line argument to gain full control of the device using SSH or telnet if they already have network access.
Talos also alerted Lenovo that the clock’s hardcoded root password is weak and easily guessed or cracked. Even on low-end hardware, and with a basic dictionary, the brute force took less
https://consumer.huawei.com/en/support/bulletin/2023/4/https://device.harmonyos.com/en/docs/security/update/security-bulletins-202304-0000001506528486https://consumer.huawei.com/en/support/bulletin/2023/4/https://device.harmonyos.com/en/docs/security/update/security-bulletins-202304-0000001506528486
2023-05-20
Published