CVE Vulnerabilities

CVE-2024-47293

Improper Handling of Length Parameter Inconsistency

Published: Sep 27, 2024 | Modified: Oct 01, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affect availability.

Weakness

The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

Affected Software

NameVendorStart VersionEnd Version
EmuiHuawei13.0.0 (including)13.0.0 (including)
EmuiHuawei14.0.0 (including)14.0.0 (including)
HarmonyosHuawei3.0.0 (including)3.0.0 (including)
HarmonyosHuawei4.0.0 (including)4.0.0 (including)
HarmonyosHuawei4.2.0 (including)4.2.0 (including)

Potential Mitigations

References