ID

VAR-202211-0326


CVE

CVE-2022-44562


TITLE

Huawei  of  EMUI  and  HarmonyOS  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2022-020501

DESCRIPTION

The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. Huawei of EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.71

sources: NVD: CVE-2022-44562 // JVNDB: JVNDB-2022-020501 // VULHUB: VHN-441952

AFFECTED PRODUCTS

vendor:huaweimodel:harmonyosscope:eqversion:2.0

Trust: 1.0

vendor:huaweimodel:harmonyosscope:eqversion:3.0.0

Trust: 1.0

vendor:huaweimodel:emuiscope:eqversion:12.0.0

Trust: 1.0

vendor:huaweimodel:emuiscope:eqversion:12.0.1

Trust: 1.0

vendor:huaweimodel:harmonyosscope:eqversion:2.1

Trust: 1.0

vendor:huaweimodel:emuiscope:eqversion:11.0.1

Trust: 1.0

vendor:huaweimodel:harmonyosscope: - version: -

Trust: 0.8

vendor:huaweimodel:emuiscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-020501 // NVD: CVE-2022-44562

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-44562
value: CRITICAL

Trust: 1.0

NVD: CVE-2022-44562
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202211-2133
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2022-44562
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2022-44562
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-020501 // CNNVD: CNNVD-202211-2133 // NVD: CVE-2022-44562

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD evaluation ]

Trust: 0.8

problemtype:CWE-269

Trust: 0.1

sources: VULHUB: VHN-441952 // JVNDB: JVNDB-2022-020501 // NVD: CVE-2022-44562

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202211-2133

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202211-2133

PATCH

title:Huawei HarmonyOS Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=213973

Trust: 0.6

sources: CNNVD: CNNVD-202211-2133

EXTERNAL IDS

db:NVDid:CVE-2022-44562

Trust: 3.3

db:JVNDBid:JVNDB-2022-020501

Trust: 0.8

db:CNNVDid:CNNVD-202211-2133

Trust: 0.6

db:VULHUBid:VHN-441952

Trust: 0.1

sources: VULHUB: VHN-441952 // JVNDB: JVNDB-2022-020501 // CNNVD: CNNVD-202211-2133 // NVD: CVE-2022-44562

REFERENCES

url:https://consumer.huawei.com/en/support/bulletin/2022/11/

Trust: 2.5

url:https://device.harmonyos.com/en/docs/security/update/security-bulletins-phones-202211-0000001441016433

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2022-44562

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-44562/

Trust: 0.6

url:https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202211-0000001440896653

Trust: 0.6

sources: VULHUB: VHN-441952 // JVNDB: JVNDB-2022-020501 // CNNVD: CNNVD-202211-2133 // NVD: CVE-2022-44562

SOURCES

db:VULHUBid:VHN-441952
db:JVNDBid:JVNDB-2022-020501
db:CNNVDid:CNNVD-202211-2133
db:NVDid:CVE-2022-44562

LAST UPDATE DATE

2024-08-14T14:49:31.093000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-441952date:2022-11-10T00:00:00
db:JVNDBid:JVNDB-2022-020501date:2023-11-02T08:02:00
db:CNNVDid:CNNVD-202211-2133date:2022-11-14T00:00:00
db:NVDid:CVE-2022-44562date:2023-08-08T14:22:24.967

SOURCES RELEASE DATE

db:VULHUBid:VHN-441952date:2022-11-09T00:00:00
db:JVNDBid:JVNDB-2022-020501date:2023-11-02T00:00:00
db:CNNVDid:CNNVD-202211-2133date:2022-11-05T00:00:00
db:NVDid:CVE-2022-44562date:2022-11-09T21:15:18.920