CVE-2022-38980

CRITICAL

HarmonyOS - Heap Overflow in HwAirlink Module

Title source: llm
STIX 2.1

Description

The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.

Scores

CVSS v3 9.8
EPSS 0.0022
EPSS Percentile 45.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-787
Status published
Products (2)
huawei/harmonyos 2.0
huawei/harmonyos 2.1
Published Oct 14, 2022
Tracked Since Feb 18, 2026