ID

VAR-202212-0487


CVE

CVE-2022-46316


TITLE

Huawei  of  HarmonyOS  Authentication vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2022-023889

DESCRIPTION

A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability. Huawei of HarmonyOS There is an authentication vulnerability in.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.71

sources: NVD: CVE-2022-46316 // JVNDB: JVNDB-2022-023889 // VULHUB: VHN-444286

AFFECTED PRODUCTS

vendor:huaweimodel:harmonyosscope:ltversion:2.1

Trust: 1.0

vendor:huaweimodel:harmonyosscope:eqversion:2.1

Trust: 0.8

vendor:huaweimodel:harmonyosscope:eqversion: -

Trust: 0.8

vendor:huaweimodel:harmonyosscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2022-023889 // NVD: CVE-2022-46316

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-46316
value: CRITICAL

Trust: 1.0

NVD: CVE-2022-46316
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202212-2493
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2022-46316
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2022-46316
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2022-023889 // CNNVD: CNNVD-202212-2493 // NVD: CVE-2022-46316

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.1

problemtype:Inappropriate authentication (CWE-287) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-444286 // JVNDB: JVNDB-2022-023889 // NVD: CVE-2022-46316

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202212-2493

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202212-2493

PATCH

title:Huawei HarmonyOS Remediation measures for authorization problem vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=218949

Trust: 0.6

sources: CNNVD: CNNVD-202212-2493

EXTERNAL IDS

db:NVDid:CVE-2022-46316

Trust: 3.3

db:JVNDBid:JVNDB-2022-023889

Trust: 0.8

db:CNNVDid:CNNVD-202212-2493

Trust: 0.6

db:VULHUBid:VHN-444286

Trust: 0.1

sources: VULHUB: VHN-444286 // JVNDB: JVNDB-2022-023889 // CNNVD: CNNVD-202212-2493 // NVD: CVE-2022-46316

REFERENCES

url:https://device.harmonyos.com/en/docs/security/update/security-bulletins-202212-0000001462975397

Trust: 2.5

url:https://nvd.nist.gov/vuln/detail/cve-2022-46316

Trust: 0.8

url:https://cxsecurity.com/cveshow/cve-2022-46316/

Trust: 0.6

url:https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202212-0000001462975397

Trust: 0.6

sources: VULHUB: VHN-444286 // JVNDB: JVNDB-2022-023889 // CNNVD: CNNVD-202212-2493 // NVD: CVE-2022-46316

SOURCES

db:VULHUBid:VHN-444286
db:JVNDBid:JVNDB-2022-023889
db:CNNVDid:CNNVD-202212-2493
db:NVDid:CVE-2022-46316

LAST UPDATE DATE

2024-08-14T15:16:21.013000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-444286date:2022-12-24T00:00:00
db:JVNDBid:JVNDB-2022-023889date:2023-11-30T04:33:00
db:CNNVDid:CNNVD-202212-2493date:2022-12-26T00:00:00
db:NVDid:CVE-2022-46316date:2022-12-24T04:15:25.557

SOURCES RELEASE DATE

db:VULHUBid:VHN-444286date:2022-12-20T00:00:00
db:JVNDBid:JVNDB-2022-023889date:2023-11-30T00:00:00
db:CNNVDid:CNNVD-202212-2493date:2022-12-05T00:00:00
db:NVDid:CVE-2022-46316date:2022-12-20T21:15:11.443