CVE-2023-0036

MEDIUM

OpenHarmony <v3.0.5 - Auth Bypass

Title source: llm

Description

platform_callback_stub in misc subsystem within OpenHarmony-v3.0.5 and prior versions has an authentication bypass vulnerability which allows an "SA relay attack".Local attackers can bypass authentication and attack other SAs with high privilege.

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 14.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Classification

CWE
CWE-287 CWE-294
Status published

Affected Products (1)

openatom/openharmony < 3.0.5

Timeline

Published Jan 09, 2023
Tracked Since Feb 18, 2026