Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
The vulnerability results from improper package name verification (CWE-347: improper verification of cryptographic signature, CWE-863: incorrect authorization) in the HwIms module. An attacker can remotely, without authentication and without user interaction, deliver a crafted request bypassing the package name control mechanism. As a result, the HwIms module can be induced to perform unauthorized operations.
Successful exploitation of the vulnerability allows an attacker to compromise data integrity and disrupt the availability of the system or services related to the HwIms module.
Patches available from the vendor should be applied in accordance with references — Huawei security bulletin from March 2024 available at https://consumer.huawei.com/en/support/bulletin/2024/3/
Huawei devices with EMUI and HarmonyOS systems — specific versions indicated in vendor references (Huawei security bulletin from March 2024).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HHuawei Emui
OSHuawei12.0.013.0.0Huawei Harmonyos
OSHuawei2.0.02.1.03.0.03.1.04.0.0
Related vulnerabilities
HarmonyOS: przepełnienie bufora sterty (heap buffer overflow) w module WEB
Pominięcie uwierzytelnienia w module autoryzacji urządzeń Huawei HarmonyOS
Błąd kontroli uprawnień w module zarządzania pamięcią Huawei HarmonyOS
Nieobsłużony wyjątek w module Graphics systemów Huawei EMUI/HarmonyOS
Podatność kontroli dostępu w module weryfikacji bezpieczeństwa Huawei