Impact
This vulnerability represents an insufficient permission control flaw within the event notification module of Huawei HarmonyOS. The flaw allows an attacker to bypass expected authorization checks (CWE‑275) and trigger or manipulate events that the system normally restricts. Because the event notification functionality may be used to schedule tasks or execute code, unauthorized access could potentially disrupt service operation, leading to availability degradation.
Affected Systems
The affected vendor is Huawei, with the product HarmonyOS. No specific version range is listed in the advisory, so all deployments of HarmonyOS are potentially impacted until an official fix becomes available.
Risk and Exploitability
The CVSS score of 6.2 reflects a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation at this time. The likely attack vector is local or requires an authenticated user on the device, as the flaw involves privileged permission checks. Effective monitoring and timely patching should mitigate the risk.
OpenCVE Enrichment