Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-42463


OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary commands.


Published

2022-10-14T15:16:24.883

Last Modified

2024-11-21T07:25:00.773

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.3 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-287
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openharmony openharmony ≤ 3.1.2 Yes

References