Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.
The vulnerability consists of a stack overflow in the NFC communication module. An attacker can send crafted data through the NFC interface, causing the reserved stack area to be exceeded. This can lead to service disruption or unauthorized modification of data processed by the module.
An attacker can cause denial of service and compromise data integrity on a vulnerable device.
Security patches from the manufacturer should be applied in accordance with references — Huawei security bulletin from February 2024 available at https://consumer.huawei.com/en/support/bulletin/2024/2/
Devices running Huawei EMUI and HarmonyOS — specific versions indicated in manufacturer references (Huawei security bulletin from February 2024).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HHuawei Emui
OSHuawei12.0.013.0.0Huawei Harmonyos
OSHuawei2.0.02.1.03.0.03.1.04.0.0
Related vulnerabilities
HarmonyOS: przepełnienie bufora sterty (heap buffer overflow) w module WEB
Pominięcie uwierzytelnienia w module autoryzacji urządzeń Huawei HarmonyOS
Błąd kontroli uprawnień w module zarządzania pamięcią Huawei HarmonyOS
Nieobsłużony wyjątek w module Graphics systemów Huawei EMUI/HarmonyOS
Podatność kontroli dostępu w module weryfikacji bezpieczeństwa Huawei