CVE-2023-34165Missing Authorization in Huawei Harmonyos

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 79.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 16

Description

Unauthorized access vulnerability in the Save for later feature provided by AI Touch.Successful exploitation of this vulnerability may cause third-party apps to forge a URI for unauthorized access with zero permissions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5huawei/harmonyos2.1.0

🔴Vulnerability Details

1
GHSA
GHSA-jm4w-v2xf-52jr: Unauthorized access vulnerability in the Save for later feature provided by AI Touch2023-06-16