CVE-2022-48291

MEDIUM

Huawei EMUI and HarmonyOS - Authentication Bypass in Bluetooth Pairing Process

Title source: llm
STIX 2.1

Description

The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this vulnerability may affect confidentiality.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 13.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (8)
huawei/emui 11.0.1
huawei/emui 12.0.0
huawei/emui 12.0.1
huawei/emui 13.0.0
huawei/harmonyos 2.0.0
huawei/harmonyos 2.0.1
huawei/harmonyos 3.0.0
huawei/harmonyos 3.1.0
Published Mar 27, 2023
Tracked Since Feb 18, 2026