Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
The vulnerability results from improper implementation of access control mechanisms in the security verification module. A local attacker, without possessing any privileges and without user interaction, can bypass security verification mechanisms. The scope of impact extends beyond the direct component (S:C), indicating potential to affect other system elements.
Successful exploitation may lead to breach of confidentiality, integrity, and availability of data and system services. An attacker may gain unauthorized access to protected system resources.
Apply patches available from the manufacturer according to references — Huawei security bulletin from July 2024: https://consumer.huawei.com/en/support/bulletin/2024/7/
Huawei devices with EMUI and HarmonyOS systems — specific versions indicated in manufacturer references (Huawei security bulletin from July 2024)
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHuawei Emui
OSHuawei14.0.0Huawei Harmonyos
OSHuawei4.0.04.2.0
Related vulnerabilities
HarmonyOS: przepełnienie bufora sterty (heap buffer overflow) w module WEB
Pominięcie uwierzytelnienia w module autoryzacji urządzeń Huawei HarmonyOS
Błąd kontroli uprawnień w module zarządzania pamięcią Huawei HarmonyOS
Nieobsłużony wyjątek w module Graphics systemów Huawei EMUI/HarmonyOS
Ominięcie weryfikacji nazwy pakietu w module HwIms (Huawei EMUI/HarmonyOS)