Lucene search

K
nvd[email protected]NVD:CVE-2022-41592
HistoryOct 14, 2022 - 4:15 p.m.

CVE-2022-41592

2022-10-1416:15:26
CWE-125
CWE-476
CWE-787
web.nvd.nist.gov
6
phones
heap overflow
fingerprint
vulnerabilities
out-of-bounds read
null pointer

CVSS3

3.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

EPSS

0

Percentile

12.6%

The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.

Affected configurations

Nvd
Node
huaweiemuiMatch11.0.1
OR
huaweiemuiMatch12.0.0
OR
huaweiharmonyosMatch2.0
VendorProductVersionCPE
huaweiemui11.0.1cpe:2.3:o:huawei:emui:11.0.1:*:*:*:*:*:*:*
huaweiemui12.0.0cpe:2.3:o:huawei:emui:12.0.0:*:*:*:*:*:*:*
huaweiharmonyos2.0cpe:2.3:o:huawei:harmonyos:2.0:*:*:*:*:*:*:*

CVSS3

3.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

EPSS

0

Percentile

12.6%

Related for NVD:CVE-2022-41592