First published: Mon Jun 13 2022(Updated: )
Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploitation of this vulnerability may affect data integrity and confidentiality.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei EMUI | =10.1.0 | |
Huawei EMUI | =10.1.1 | |
Huawei EMUI | =11.0.0 | |
Huawei EMUI | =12.0.0 | |
Huawei HarmonyOS | =2.0 | |
Huawei Magic UI | =3.1.0 | |
Huawei Magic UI | =3.1.1 | |
Huawei Magic UI | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-31760 is considered moderate due to potential risks to data integrity and confidentiality.
To fix CVE-2022-31760, update affected Huawei devices to the latest firmware provided by Huawei.
CVE-2022-31760 affects specific versions of Huawei EMUI, HarmonyOS, and Magic UI.
Exploitation of CVE-2022-31760 may lead to unauthorized data exposure even when the device screen is locked.
CVE-2022-31760 can potentially be exploited through carrier-customized USSD services.