CVE-2022-38081: Tokensync in security subsystem has a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system.
Published Sep 9, 2022
·Updated
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to obtain system.
Affected Software
1 affected component
OpenHarmony OpenHarmony>=3.1<=3.1.2
Event History
Sep 9, 2022
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-38081?
CVE-2022-38081 is a permission bypass vulnerability in OpenHarmony-v3.1.2 and prior versions.
2
What is the severity of CVE-2022-38081?
CVE-2022-38081 has a severity rating of 5.5 (medium).
3
How does CVE-2022-38081 work?
CVE-2022-38081 allows LAN attackers to bypass the distributed permission control in OpenHarmony-v3.1.2 and prior versions.
4
How can an attacker exploit CVE-2022-38081?
To exploit CVE-2022-38081, an attacker would need another vulnerability to obtain system access.
5
Is there a fix for CVE-2022-38081?
It is recommended to update to a version of OpenHarmony that is not affected by this vulnerability.