ID

VAR-202209-0366


CVE

CVE-2022-38999


TITLE

Huawei  of  EMUI  and  HarmonyOS  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2022-017155

DESCRIPTION

The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability. Huawei of EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.8

sources: NVD: CVE-2022-38999 // JVNDB: JVNDB-2022-017155 // VULHUB: VHN-434770 // VULMON: CVE-2022-38999

AFFECTED PRODUCTS

vendor:huaweimodel:emuiscope:eqversion:12.0.0

Trust: 1.0

vendor:huaweimodel:harmonyosscope:eqversion:2.0

Trust: 1.0

vendor:huaweimodel:emuiscope: - version: -

Trust: 0.8

vendor:huaweimodel:harmonyosscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-017155 // NVD: CVE-2022-38999

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-38999
value: CRITICAL

Trust: 1.0

NVD: CVE-2022-38999
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202209-170
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2022-38999
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2022-38999
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-017155 // CNNVD: CNNVD-202209-170 // NVD: CVE-2022-38999

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:others (CWE-Other) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-017155 // NVD: CVE-2022-38999

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202209-170

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202209-170

PATCH

title:Huawei HarmonyOS Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=208080

Trust: 0.6

sources: CNNVD: CNNVD-202209-170

EXTERNAL IDS

db:NVDid:CVE-2022-38999

Trust: 3.4

db:JVNDBid:JVNDB-2022-017155

Trust: 0.8

db:CNNVDid:CNNVD-202209-170

Trust: 0.6

db:VULHUBid:VHN-434770

Trust: 0.1

db:VULMONid:CVE-2022-38999

Trust: 0.1

sources: VULHUB: VHN-434770 // VULMON: CVE-2022-38999 // JVNDB: JVNDB-2022-017155 // CNNVD: CNNVD-202209-170 // NVD: CVE-2022-38999

REFERENCES

url:https://consumer.huawei.com/en/support/bulletin/2022/9/

Trust: 2.6

url:https://device.harmonyos.com/en/docs/security/update/security-bulletins-phones-202209-0000001392278845

Trust: 2.6

url:https://nvd.nist.gov/vuln/detail/cve-2022-38999

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-38999/

Trust: 0.6

url:https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202209-0000001392078921

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-434770 // VULMON: CVE-2022-38999 // JVNDB: JVNDB-2022-017155 // CNNVD: CNNVD-202209-170 // NVD: CVE-2022-38999

SOURCES

db:VULHUBid:VHN-434770
db:VULMONid:CVE-2022-38999
db:JVNDBid:JVNDB-2022-017155
db:CNNVDid:CNNVD-202209-170
db:NVDid:CVE-2022-38999

LAST UPDATE DATE

2024-08-14T15:16:30.332000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-434770date:2022-09-20T00:00:00
db:VULMONid:CVE-2022-38999date:2022-09-16T00:00:00
db:JVNDBid:JVNDB-2022-017155date:2023-10-11T08:51:00
db:CNNVDid:CNNVD-202209-170date:2022-09-21T00:00:00
db:NVDid:CVE-2022-38999date:2022-09-20T18:58:51.147

SOURCES RELEASE DATE

db:VULHUBid:VHN-434770date:2022-09-16T00:00:00
db:VULMONid:CVE-2022-38999date:2022-09-16T00:00:00
db:JVNDBid:JVNDB-2022-017155date:2023-10-11T00:00:00
db:CNNVDid:CNNVD-202209-170date:2022-09-05T00:00:00
db:NVDid:CVE-2022-38999date:2022-09-16T18:15:17.860