Lucene search

K
cvelistHuaweiCVELIST:CVE-2022-48518
HistoryJul 06, 2023 - 12:53 p.m.

CVE-2022-48518

2023-07-0612:53:19
CWE-701
huawei
www.cve.org
vulnerability
signature verification
iaware system
spoofing
trustlist
system performance

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "HarmonyOS",
    "vendor": "Huawei",
    "versions": [
      {
        "status": "affected",
        "version": "2.0.0"
      },
      {
        "status": "affected",
        "version": "2.0.1"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "EMUI",
    "vendor": "Huawei",
    "versions": [
      {
        "status": "affected",
        "version": "12.0.0"
      },
      {
        "status": "affected",
        "version": "12.0.1"
      }
    ]
  }
]

5.6 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

Related for CVELIST:CVE-2022-48518