First published: Thu Dec 08 2022(Updated: )
OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.
Credit: scy@openharmony.io scy@openharmony.io
Affected Software | Affected Version | How to fix |
---|---|---|
Openharmony Openharmony | >=3.1<=3.1.4 | |
>=3.1<=3.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-45877.
The severity of CVE-2022-45877 is high with a severity value of 5.3.
CVE-2022-45877 is a vulnerability in OpenHarmony-v3.1.4 and prior versions where the PIN code is transmitted to the peer device in plain text during cross-device authentication, making it vulnerable to man-in-the-middle attacks.
OpenHarmony-v3.1.4 and prior versions are affected by CVE-2022-45877.
To mitigate CVE-2022-45877, it is recommended to update to a version higher than v3.1.4 of OpenHarmony.