Impact
The vulnerability is a permission control flaw located in the clone module of Huawei HarmonyOS. When triggered, it can allow an attacker to gain unauthorized access, thereby compromising the confidentiality of the affected services. The weakness corresponds to CWE‑275, where operations permitted to a user are insufficiently restricted.
Affected Systems
The flaw affects Huawei HarmonyOS. Specific product or component designates the clone module. No version details are supplied, so all installations of HarmonyOS that include the clone module are potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.4 indicates modest severity. No EPSS value is supplied, so the potential exploitation frequency is unclear. The vulnerability is not listed in CISA KEV, suggesting no known public exploitation. The attack vector is not explicitly defined in the advisory; it is inferred that, lacking details, the vulnerability may require local or privileged access, but this cannot be confirmed.
OpenCVE Enrichment