Lucene search

K
cve[email protected]CVE-2022-41603
HistoryOct 14, 2022 - 4:15 p.m.

CVE-2022-41603

2022-10-1416:15:30
CWE-476
CWE-787
CWE-125
web.nvd.nist.gov
19
4
cve-2022-41603
phones
heap overflow
out-of-bounds read
null pointer
fingerprint ta
vulnerabilities
fingerprint service
nvd

3.4 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

4.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.7%

The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

Affected configurations

NVD
Node
huaweiemuiMatch11.0.1
OR
huaweiemuiMatch12.0.0
OR
huaweiharmonyosMatch2.0

CNA Affected

[
  {
    "vendor": "Huawei",
    "product": "HarmonyOS",
    "versions": [
      {
        "version": "2.0",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Huawei",
    "product": "EMUI",
    "versions": [
      {
        "version": "12.0.0",
        "status": "affected"
      },
      {
        "version": "11.0.1",
        "status": "affected"
      }
    ]
  }
]

Social References

More

3.4 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

4.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

12.7%

Related for CVE-2022-41603