CVE-2022-48289: High severity emui 5.0 vulnerability
Published Feb 9, 2023
·Updated
The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this vulnerability may affect data confidentiality.
Affected Software
3 affected components
Huawei Emui=12.0.1
Huawei Harmonyos=2.0.1
Huawei Harmonyos=3.0.0
Event History
Feb 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-48289?
CVE-2022-48289 is considered to have a medium severity level due to potential data confidentiality risks.
2
How do I fix CVE-2022-48289?
To fix CVE-2022-48289, ensure you update to the latest version of Huawei Emui or HarmonyOS that contains the relevant security patches.
3
What systems are affected by CVE-2022-48289?
CVE-2022-48289 affects Huawei Emui version 12.0.1 and HarmonyOS versions 2.0.1 and 3.0.0.
4
What types of exploit are possible with CVE-2022-48289?
Exploitation of CVE-2022-48289 could allow unauthorized access to sensitive data due to lack of authentication and control mechanisms.
5
Is there a workaround for CVE-2022-48289 until a patch is applied?
Currently, there is no official workaround for CVE-2022-48289 other than updating the affected systems promptly.