Lucene search

K
nvd[email protected]NVD:CVE-2022-48518
HistoryJul 06, 2023 - 1:15 p.m.

CVE-2022-48518

2023-07-0613:15:10
CWE-701
CWE-665
web.nvd.nist.gov
vulnerability
iaware system
signature verification
delay
malicious apps
startups
system performance

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

0.0004 Low

EPSS

Percentile

15.5%

Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.

Affected configurations

NVD
Node
huaweiemuiMatch12.0.0
OR
huaweiemuiMatch12.0.1
OR
huaweiharmonyosMatch2.0.0
OR
huaweiharmonyosMatch2.0.1

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

0.0004 Low

EPSS

Percentile

15.5%

Related for NVD:CVE-2022-48518