CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-52369

CVSS 9.1v3.1pub. 2024-02-18upd. 2025-03-25

Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.

🤖 AI Analysis
How it works

The vulnerability consists of a stack overflow in the NFC communication module. An attacker can send crafted data through the NFC interface, causing the reserved stack area to be exceeded. This can lead to service disruption or unauthorized modification of data processed by the module.

Impact

An attacker can cause denial of service and compromise data integrity on a vulnerable device.

Mitigation & patch

Security patches from the manufacturer should be applied in accordance with references — Huawei security bulletin from February 2024 available at https://consumer.huawei.com/en/support/bulletin/2024/2/

Who is affected

Devices running Huawei EMUI and HarmonyOS — specific versions indicated in manufacturer references (Huawei security bulletin from February 2024).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Huawei Emui

    OS
    Huawei
    12.0.013.0.0
  • Huawei Harmonyos

    OS
    Huawei
    2.0.02.1.03.0.03.1.04.0.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-34865CRITICAL10.0PL ✓same product

HarmonyOS: przepełnienie bufora sterty (heap buffer overflow) w module WEB

CVE-2026-28536CRITICAL9.6PL ✓same product

Pominięcie uwierzytelnienia w module autoryzacji urządzeń Huawei HarmonyOS

CVE-2025-64314CRITICAL9.3PL ✓same product

Błąd kontroli uprawnień w module zarządzania pamięcią Huawei HarmonyOS

CVE-2024-42037CRITICAL9.3PL ✓same product

Nieobsłużony wyjątek w module Graphics systemów Huawei EMUI/HarmonyOS

CVE-2024-39671CRITICAL9.3PL ✓same product

Podatność kontroli dostępu w module weryfikacji bezpieczeństwa Huawei