CVE-2022-37008: High severity Huawei Emui vulnerability
Published Aug 9, 2022
·Updated
The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.
Affected Software
5 affected components
Huawei Emui=11.0.0
Huawei Emui=11.0.1
Huawei Emui=12.0.0
Huawei Harmonyos=2.0
Huawei Magic Ui=4.0.0
Event History
Aug 9, 2022
CVE Published
via MITRE·08:10 PM
Data Sourced
via MITRE·08:10 PM
DescriptionWeakness
Aug 10, 2022
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-37008?
CVE-2022-37008 has been classified as a medium severity vulnerability.
2
What devices are affected by CVE-2022-37008?
CVE-2022-37008 affects Huawei EMUI versions 11.0.0, 11.0.1, 12.0.0, Huawei HarmonyOS 2.0, and Huawei Magic UI 4.0.0.
3
How do I fix CVE-2022-37008?
To fix CVE-2022-37008, ensure your device is updated to the latest security patches provided by Huawei.
4
What happens if CVE-2022-37008 is exploited?
Exploitation of CVE-2022-37008 may lead to instability in the system.
5
Is CVE-2022-37008 remotely exploitable?
CVE-2022-37008 requires user interaction to exploit, as it involves the update package verification process.