2023-10-11 14:00:28 +00:00
{
"id" : "CVE-2023-44116" ,
"sourceIdentifier" : "psirt@huawei.com" ,
"published" : "2023-10-11T13:15:10.160" ,
2023-10-15 02:00:27 +00:00
"lastModified" : "2023-10-15T01:49:29.117" ,
"vulnStatus" : "Analyzed" ,
2023-10-11 14:00:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized."
2023-10-15 02:00:27 +00:00
} ,
{
"lang" : "es" ,
"value" : "Vulnerabilidad de que los permisos de acceso no se verifican estrictamente en el m\u00f3dulo APPWidget. La explotaci\u00f3n exitosa de esta vulnerabilidad puede causar que algunas aplicaciones se ejecuten sin autorizaci\u00f3n."
2023-10-11 14:00:28 +00:00
}
] ,
2023-10-15 02:00:27 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
}
]
} ,
2023-10-11 14:00:28 +00:00
"weaknesses" : [
2023-10-15 02:00:27 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-306"
}
]
} ,
2023-10-11 14:00:28 +00:00
{
"source" : "psirt@huawei.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-306"
}
]
}
] ,
2023-10-15 02:00:27 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:huawei:harmonyos:2.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "20112231-B840-44D3-A061-B9B9F80EE378"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:huawei:harmonyos:2.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "64118936-E2A5-4935-8594-29DF29B5475A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:huawei:harmonyos:2.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C01447F1-7F58-4AE3-B403-C01B2575D898"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:huawei:harmonyos:3.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CB3751C1-7729-41D3-AE50-80B5AF601135"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:huawei:harmonyos:3.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4D81C4EF-7CAF-4E60-91A4-8CF7B95B2B54"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:huawei:harmonyos:4.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8198CDB2-4BC5-411A-8736-615A531FC545"
}
]
}
]
} ,
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:huawei:emui:11.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "511F8CE2-C2B6-4A08-B992-49D9B75B8655"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:huawei:emui:12.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A974CA73-84E8-480B-BB4C-4A81D0C985B2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:huawei:emui:12.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2DF07E7F-3A18-4B74-B73D-DF3647C2A48F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:huawei:emui:13.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "353AEAF2-AF46-4835-93E1-4F942D5E2810"
}
]
}
]
}
] ,
2023-10-11 14:00:28 +00:00
"references" : [
{
"url" : "https://consumer.huawei.com/en/support/bulletin/2023/10/" ,
2023-10-15 02:00:27 +00:00
"source" : "psirt@huawei.com" ,
"tags" : [
"Vendor Advisory"
]
2023-10-11 14:00:28 +00:00
} ,
{
"url" : "https://device.harmonyos.com/en/docs/security/update/security-bulletins-202310-0000001663676540" ,
2023-10-15 02:00:27 +00:00
"source" : "psirt@huawei.com" ,
"tags" : [
"Vendor Advisory"
]
2023-10-11 14:00:28 +00:00
}
]
}