CVE Vulnerabilities

CVE-2024-47293

Improper Handling of Length Parameter Inconsistency

Published: Sep 27, 2024 | Modified: Oct 01, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affect availability.

Weakness

The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.

Affected Software

Name Vendor Start Version End Version
Emui Huawei 13.0.0 (including) 13.0.0 (including)
Emui Huawei 14.0.0 (including) 14.0.0 (including)
Harmonyos Huawei 3.0.0 (including) 3.0.0 (including)
Harmonyos Huawei 4.0.0 (including) 4.0.0 (including)
Harmonyos Huawei 4.2.0 (including) 4.2.0 (including)

Potential Mitigations

References