Impact
The vulnerability is a permission control flaw in Huawei’s AMS module, identified as CWE-264. An attacker who can obtain elevated or unauthorized access to AMS code can disrupt device operation, resulting in denial‑of‑service or other availability degradation. No other impacts such as confidentiality or integrity are mentioned in the CVE data.
Affected Systems
Affected are Huawei EMUI 14.2.0 and 15.0.0, and Huawei HarmonyOS 4.2.0, 4.3.0, and 4.3.1, as listed in the CPE entries.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not cataloged in CISA KEV. Because the attack vector is not stated explicitly, it is inferred that local compromise or device credential abuse is required to exploit the permission flaw.
OpenCVE Enrichment