CVE Vulnerabilities

CVE-2023-44104

Incorrect Resource Transfer Between Spheres

Published: Oct 11, 2023 | Modified: Oct 16, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability may affect service confidentiality.

Weakness

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

Affected Software

Name Vendor Start Version End Version
Harmonyos Huawei 2.0.0 (including) 2.0.0 (including)
Harmonyos Huawei 2.0.1 (including) 2.0.1 (including)
Harmonyos Huawei 2.1.0 (including) 2.1.0 (including)
Harmonyos Huawei 3.0.0 (including) 3.0.0 (including)
Harmonyos Huawei 3.1.0 (including) 3.1.0 (including)
Harmonyos Huawei 4.0.0 (including) 4.0.0 (including)

References