Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-48518


Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.


Published

2023-07-06T13:15:10.563

Last Modified

2024-11-21T07:33:29.100

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-701
  • Type: Primary
    CWE-665

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System huawei emui 12.0.0 Yes
Operating System huawei emui 12.0.1 Yes
Operating System huawei harmonyos 2.0.0 Yes
Operating System huawei harmonyos 2.0.1 Yes

References