First published: Tue Sep 06 2022(Updated: )
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system.
Credit: scy@openharmony.io
Affected Software | Affected Version | How to fix |
---|---|---|
Openharmony Openharmony | >=3.1<=3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38081 is a permission bypass vulnerability in OpenHarmony-v3.1.2 and prior versions.
CVE-2022-38081 has a severity rating of 5.5 (medium).
CVE-2022-38081 allows LAN attackers to bypass the distributed permission control in OpenHarmony-v3.1.2 and prior versions.
To exploit CVE-2022-38081, an attacker would need another vulnerability to obtain system access.
It is recommended to update to a version of OpenHarmony that is not affected by this vulnerability.