Описание
OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and obtain information such as mobile numbers and SMS data without permissions.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.1 (включая) до 3.1.4 (включая)
cpe:2.3:a:openharmony:openharmony:*:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00044
Низкий
6.2 Medium
CVSS3
5.5 Medium
CVSS3
Дефекты
CWE-287
CWE-276
Связанные уязвимости
CVSS3: 5.5
github
около 3 лет назад
OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and obtain information such as mobile numbers and SMS data without permissions.
EPSS
Процентиль: 13%
0.00044
Низкий
6.2 Medium
CVSS3
5.5 Medium
CVSS3
Дефекты
CWE-287
CWE-276