Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-42488

Опубликовано: 14 окт. 2022
Источник: nvd
CVSS3: 8.4
CVSS3: 7.8
EPSS Низкий

Описание

OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openharmony:openharmony:*:*:*:*:*:*:*:*
Версия от 3.1 (включая) до 3.1.2 (исключая)

EPSS

Процентиль: 16%
0.0005
Низкий

8.4 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-287
CWE-862

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.

EPSS

Процентиль: 16%
0.0005
Низкий

8.4 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-287
CWE-862