Lucene search

K
nvd[email protected]NVD:CVE-2022-48289
HistoryFeb 09, 2023 - 5:15 p.m.

CVE-2022-48289

2023-02-0917:15:12
CWE-306
web.nvd.nist.gov
5
vulnerability
bundle management
authentication
control mechanisms
data confidentiality

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

53.0%

The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.

Affected configurations

Nvd
Node
huaweiemuiMatch12.0.1
OR
huaweiharmonyosMatch2.0.1
OR
huaweiharmonyosMatch3.0.0
VendorProductVersionCPE
huaweiemui12.0.1cpe:2.3:o:huawei:emui:12.0.1:*:*:*:*:*:*:*
huaweiharmonyos2.0.1cpe:2.3:o:huawei:harmonyos:2.0.1:*:*:*:*:*:*:*
huaweiharmonyos3.0.0cpe:2.3:o:huawei:harmonyos:3.0.0:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

53.0%

Related for NVD:CVE-2022-48289