First published: Tue Oct 11 2022(Updated: )
OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary commands.
Credit: scy@openharmony.io
Affected Software | Affected Version | How to fix |
---|---|---|
Openharmony Openharmony | >=3.1<=3.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42463 is an authentication bypass vulnerability in OpenHarmony-v3.1.2 and prior versions.
CVE-2022-42463 allows attackers to launch attacks on distributed networks by sending Bluetooth rfcomm packets to any remote device and executing arbitrary commands.
CVE-2022-42463 has a severity of 8.8 (High).
To fix CVE-2022-42463, update OpenHarmony to version 3.1.2 or later.
More information about CVE-2022-42463 can be found at the following link: https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-10.md