Impact
The vulnerability is a permission control flaw located in the Settings module of Huawei devices. It allows an attacker with sufficient privileges to read configuration data, leading to a disclosure of confidential service information. The flaw is classified as CWE-200, which deals with information exposure due to inadequate access controls.
Affected Systems
Affected products include Huawei EMUI and Huawei HarmonyOS. The advisory does not specify affected firmware or OS versions; therefore all current releases of these products are potentially impacted until an official fix is released.
Risk and Exploitability
The CVSS score of 6.6 indicates moderate severity, and the EPSS score of less than 1% coupled with absence from the CISA KEV catalog suggest exploitation is unlikely in the near term. The attack vector is not explicitly stated, so it is inferred that the vulnerability likely requires authenticated or local privileged access. If exploited, an attacker could read sensitive configuration data but probably cannot modify settings or gain additional privileges.
OpenCVE Enrichment