CVE-2023-34154Incorrect Permission Assignment in Huawei Harmonyos

Severity
8.2HIGHNVD
EPSS
0.1%
top 75.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 16

Description

Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will cause third-party apps to create windows in an arbitrary way, consuming system resources.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:HExploitability: 3.9 | Impact: 4.2

Affected Packages2 packages

NVDhuawei/harmonyos< 2.0
CVEListV5huawei/harmonyos2.0.0, 3.0.0+1

🔴Vulnerability Details

1
GHSA
GHSA-586p-cp79-c7hv: Vulnerability of undefined permissions in HUAWEI VR screen projection2023-06-16