CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-52538

CVSS 9.1v3.1pub. 2024-04-08upd. 2025-03-25

Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

🤖 AI Analysis
How it works

The vulnerability results from improper package name verification (CWE-347: improper verification of cryptographic signature, CWE-863: incorrect authorization) in the HwIms module. An attacker can remotely, without authentication and without user interaction, deliver a crafted request bypassing the package name control mechanism. As a result, the HwIms module can be induced to perform unauthorized operations.

Impact

Successful exploitation of the vulnerability allows an attacker to compromise data integrity and disrupt the availability of the system or services related to the HwIms module.

Mitigation & patch

Patches available from the vendor should be applied in accordance with references — Huawei security bulletin from March 2024 available at https://consumer.huawei.com/en/support/bulletin/2024/3/

Who is affected

Huawei devices with EMUI and HarmonyOS systems — specific versions indicated in vendor references (Huawei security bulletin from March 2024).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Huawei Emui

    OS
    Huawei
    12.0.013.0.0
  • Huawei Harmonyos

    OS
    Huawei
    2.0.02.1.03.0.03.1.04.0.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-34865CRITICAL10.0PL ✓same product

HarmonyOS: przepełnienie bufora sterty (heap buffer overflow) w module WEB

CVE-2026-28536CRITICAL9.6PL ✓same product

Pominięcie uwierzytelnienia w module autoryzacji urządzeń Huawei HarmonyOS

CVE-2025-64314CRITICAL9.3PL ✓same product

Błąd kontroli uprawnień w module zarządzania pamięcią Huawei HarmonyOS

CVE-2024-42037CRITICAL9.3PL ✓same product

Nieobsłużony wyjątek w module Graphics systemów Huawei EMUI/HarmonyOS

CVE-2024-39671CRITICAL9.3PL ✓same product

Podatność kontroli dostępu w module weryfikacji bezpieczeństwa Huawei