The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://device.harmonyos.com/en/docs/security/update/security-bulletins-202302-0000001454769474 | vendor advisory |
https://consumer.huawei.com/en/support/bulletin/2023/2/ | vendor advisory |