CVE-2023-34160Authentication Bypass by Spoofing in Huawei Emui

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 77.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 19

Description

Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app icons on the desktop to prevent them from being uninstalled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

CVEListV5huawei/emui12.0.0, 13.0.0+1
NVDhuawei/emui12.0.0, 13.0.0+1
CVEListV5huawei/harmonyos4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-ccg9-9wjx-8536: Vulnerability of spoofing trustlists of Huawei desktop2023-06-19
CVEList
CVE-2023-34160: Vulnerability of spoofing trustlists of Huawei desktop2023-06-19
CVE-2023-34160 — Authentication Bypass by Spoofing | cvebase