CVE-2022-48288: High severity emui 5.0 vulnerability
Published Feb 9, 2023
·Updated
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
Affected Software
3 affected components
Huawei Emui=12.0.1
Huawei Harmonyos=2.0.1
Huawei Harmonyos=3.0.0
Event History
Feb 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-48288?
The severity of CVE-2022-48288 is classified as critical due to its potential impact on data confidentiality.
2
How do I fix CVE-2022-48288?
To fix CVE-2022-48288, update your Huawei Emui or Harmonyos software to the latest patched version.
3
Which versions are affected by CVE-2022-48288?
CVE-2022-48288 affects Huawei Emui version 12.0.1 and Harmonyos versions 2.0.1 and 3.0.0.
4
What types of attacks can exploit CVE-2022-48288?
CVE-2022-48288 can be exploited through unauthorized access to APIs due to the lack of authentication and control mechanisms.
5
Can CVE-2022-48288 affect mobile users?
Yes, CVE-2022-48288 can affect mobile users utilizing Huawei Emui and Harmonyos devices that are running vulnerable versions.