First published: Mon Mar 07 2022(Updated: )
There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Emui | =10.0.0 | |
Huawei Emui | =10.1.0 | |
Huawei Emui | =10.1.1 | |
Huawei Emui | =11.0.0 | |
Huawei Emui | =11.0.1 | |
Huawei Emui | =12.0.0 | |
Huawei Harmonyos | =2.0 | |
Huawei Magic Ui | =3.1.0 | |
Huawei Magic Ui | =3.1.1 | |
Huawei Magic Ui | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40049 is a permission control vulnerability in the PMS module.
The severity of CVE-2021-40049 is high, with a CVSS score of 7.5.
The affected software of CVE-2021-40049 includes Huawei Emui versions 10.0.0, 10.1.0, 10.1.1, 11.0.0, 11.0.1, 12.0.0, Huawei Harmonyos version 2.0, and Huawei Magic Ui versions 3.1.0, 3.1.1, 4.0.0.
CVE-2021-40049 can be exploited to obtain sensitive system information without authorization.
More information about CVE-2021-40049 can be found at the following references: - [Huawei Support Bulletin](https://consumer.huawei.com/en/support/bulletin/2022/3/) - [HarmonyOS Security Bulletins](https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202203-0000001257385193)