Impact
The vulnerability is an out‑of‑bounds memory access within the frequency modulation module of Huawei EMUI and HarmonyOS. An attacker who can trigger this fault could cause the affected system to crash or become unresponsive, leading to a denial‑of‑service condition. This weakness is classified as CWE‑416 and has been rated moderate in severity.
Affected Systems
Huawei devices running EMUI 14.0.0, 14.2.0, 15.0.0 or HarmonyOS versions 4.0.0 to 4.3.1 are impacted. The affected CPE entries in the official advisory list specify those operating system versions.
Risk and Exploitability
The assigned CVSS score of 5.5 reflects moderate impact. The EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be local or through a malicious application that can invoke the frequency modulation API; the official advisory does not specify a remote vector. Given the medium severity and low exploitation probability, the risk to unpatched devices remains moderate but should not be ignored.
OpenCVE Enrichment