CVE-2022-48514

HIGH

HarmonyOS - Exposure of Sensitive Information via Sepolicy Netlink Permission Misconfiguration

Title source: llm
STIX 2.1

Description

The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerability may affect confidentiality.

Scores

CVSS v3 7.5
EPSS 0.0014
EPSS Percentile 34.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
huawei/harmonyos 2.1.0
Published Jul 06, 2023
Tracked Since Feb 18, 2026