Vulnerabilities > CVE-2023-37242 - Authorization Bypass Through User-Controlled Key vulnerability in Huawei Emui and Harmonyos

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
huawei
CWE-639
critical

Summary

Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.

Vulnerable Configurations

Part Description Count
OS
Huawei
4