CVE-2022-45877: PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.
Published Dec 8, 2022
·Updated
OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.
Affected Software
1 affected component
OpenHarmony OpenHarmony>=3.1<=3.1.4
Event History
Dec 8, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-45877.
2
What is the severity of CVE-2022-45877?
The severity of CVE-2022-45877 is high with a severity value of 5.3.
3
What is the description of CVE-2022-45877?
CVE-2022-45877 is a vulnerability in OpenHarmony-v3.1.4 and prior versions where the PIN code is transmitted to the peer device in plain text during cross-device authentication, making it vulnerable to man-in-the-middle attacks.
4
Which software versions are affected by CVE-2022-45877?
OpenHarmony-v3.1.4 and prior versions are affected by CVE-2022-45877.
5
How can I mitigate CVE-2022-45877?
To mitigate CVE-2022-45877, it is recommended to update to a version higher than v3.1.4 of OpenHarmony.