Lucene search

K
cve[email protected]CVE-2023-0117
HistoryMay 26, 2023 - 5:15 p.m.

CVE-2023-0117

2023-05-2617:15:13
CWE-287
web.nvd.nist.gov
17
nvd
cve-2023-0117
online authentication
identity verification
hwkitassistant
meetime
vulnerability
exploitation
feature availability

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.5 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.4%

The online authentication provided by the hwKitAssistant lacks strict identity verification of applications. Successful exploitation of this vulnerability may affect availability of features,such as MeeTime.

Affected configurations

NVD
Node
huaweiemuiMatch13.0.0
CPENameOperatorVersion
huawei:emuihuawei emuieq13.0.0

CNA Affected

[
  {
    "vendor": "Huawei",
    "product": "HarmonyOS",
    "versions": [
      {
        "version": "3.1.0",
        "status": "affected"
      },
      {
        "version": "3.0.0",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Huawei",
    "product": "EMUI",
    "versions": [
      {
        "version": "13.0.0",
        "status": "affected"
      }
    ]
  }
]

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

5.5 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

18.4%

Related for CVE-2023-0117