Impact
This vulnerability is an out‑of‑bounds write in the DFX module, identified as CWE‑787. A successful exploitation could corrupt memory and cause the affected component to crash, potentially leading to a loss of service or denial of availability. No additional impact such as confidentiality or integrity compromise is documented in the provided description.
Affected Systems
Affected systems are Huawei EMUI 12.0.0 and later, including 14.0.0, 14.2.0, and 15.0.0, as well as Huawei HarmonyOS 4.0.0, 4.2.0, 4.3.0, and 4.3.1.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at the time of assessment. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or privileged, given the DFX module typically operates with elevated permissions; direct remote exploitation is not indicated by the available data.
OpenCVE Enrichment