Impact
The vulnerability is a permission control flaw in the file system that can allow an attacker to read or manipulate files that should be protected. It is categorized as CWE‑840, indicating that improperly configured permissions permit unauthorized access. If exploited, the flaw could compromise the confidentiality of the affected service by exposing sensitive data.
Affected Systems
The flaw affects Huawei products, specifically the EMUI interface and Harmony OS. No specific version numbers are provided, so all current releases remain potentially vulnerable until a vendor‑specified fix is released.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity level, but the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the most probable attack vector is via local or remote file system access that bypasses usual permission checks. Successful exploitation would primarily impact data confidentiality on the device or server.
OpenCVE Enrichment