OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-45557 | OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 14 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: OpenHarmony
Published:
Updated: 2025-05-14T15:16:52.107Z
Reserved: 2022-10-08T00:00:00.000Z
Link: CVE-2022-42488
Updated: 2024-08-03T13:10:40.890Z
Status : Modified
Published: 2022-10-14T15:16:26.243
Modified: 2024-11-21T07:25:03.680
Link: CVE-2022-42488
No data.
OpenCVE Enrichment
No data.
EUVD