First published: Mon Jul 11 2022(Updated: )
The SystemUI module has a vulnerability in permission control. If this vulnerability is successfully exploited, users are unaware of the service running in the background.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei EMUI | =10.0.0 | |
Huawei EMUI | =10.1.0 | |
Huawei EMUI | =10.1.1 | |
Huawei EMUI | =11.0.0 | |
Huawei EMUI | =11.0.1 | |
Huawei EMUI | =12.0.0 | |
Huawei HarmonyOS | =2.0 | |
Huawei Magic UI | =3.0.0 | |
Huawei Magic UI | =3.1.0 | |
Huawei Magic UI | =3.1.1 | |
Huawei Magic UI | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34738 is considered a high severity vulnerability due to its potential to allow unauthorized background services.
To fix CVE-2022-34738, ensure that your Huawei device is updated to the latest firmware version provided by the manufacturer.
CVE-2022-34738 affects multiple versions of Huawei EMUI, HarmonyOS, and Magic UI, specifically versions 10.0.0 to 12.0.0 and 2.0 to 4.0.0.
Exploitation of CVE-2022-34738 can lead to unauthorized services running without user awareness, compromising device security.
Yes, CVE-2022-34738 has been addressed in security bulletins released by Huawei for the affected software versions.