Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-45877


OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.


Published

2022-12-08T16:15:14.787

Last Modified

2024-11-21T07:29:53.193

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.3 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-287
  • Type: Primary
    CWE-319

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openharmony openharmony ≤ 3.1.4 Yes

References