Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://consumer.huawei.com/en/support/bulletin/2023/7/ | vendor advisory |
https://device.harmonyos.com/en/docs/security/update/security-bulletins-202307-0000001587168858 | vendor advisory |