CVE Vulnerabilities

CVE-2023-39392

Improper Verification of Cryptographic Signature

Published: Aug 13, 2023 | Modified: Aug 17, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Emui Huawei 12.0.1 (including) 12.0.1 (including)
Emui Huawei 13.0.0 (including) 13.0.0 (including)
Harmonyos Huawei 2.0.1 (including) 2.0.1 (including)
Harmonyos Huawei 3.0.0 (including) 3.0.0 (including)
Harmonyos Huawei 3.1.0 (including) 3.1.0 (including)

References