Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-22qq-pvp9-wmv5

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to improper permission configuration for specific operations, an attacker who obtained the Huawei ID bound to the watch can bypass permission verification to perform specific operations and modify some data on the watch.

Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to improper permission configuration for specific operations, an attacker who obtained the Huawei ID bound to the watch can bypass permission verification to perform specific operations and modify some data on the watch.

EPSS

Процентиль: 5%
0.00024
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.6
nvd
больше 6 лет назад

Huawei Watch 2 with versions and earlier than OWDD.180707.001.E1 have an improper authorization vulnerability. Due to improper permission configuration for specific operations, an attacker who obtained the Huawei ID bound to the watch can bypass permission verification to perform specific operations and modify some data on the watch.

EPSS

Процентиль: 5%
0.00024
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-863