Description
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system.
Scores
CVSS v3
6.2
EPSS
0.0004
EPSS Percentile
13.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-305
CWE-287
Status
published
Products (1)
openharmony/openharmony
3.1 - 3.1.2
Published
Sep 09, 2022
Tracked Since
Feb 18, 2026