CVE-2022-41596

HIGH

HarmonyOS < 2.1 - Unauthorized Component Startup via Deserialization Inconsistency

Title source: llm
STIX 2.1

Description

The system tool has inconsistent serialization and deserialization. Successful exploitation of this vulnerability will cause unauthorized startup of components.

Scores

CVSS v3 7.5
EPSS 0.0021
EPSS Percentile 43.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-502
Status published
Products (4)
huawei/emui 11.0.1
huawei/emui 12.0.0
huawei/emui 12.0.1
huawei/harmonyos < 2.1
Published Dec 20, 2022
Tracked Since Feb 18, 2026