First published: Mon Mar 27 2023(Updated: )
The Bluetooth module has a heap out-of-bounds write vulnerability. Successful exploitation of this vulnerability can cause the Bluetooth process to crash.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Emui | =12.0.0 | |
Huawei Emui | =13.0.0 | |
Huawei Harmonyos | =2.0 | |
Huawei Harmonyos | =2.1.0 | |
Huawei Harmonyos | =3.0.0 | |
Huawei Harmonyos | =3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-48354 is critical as it allows for a heap out-of-bounds write vulnerability in the Bluetooth module.
To fix CVE-2022-48354, update your Huawei devices to the latest firmware versions that address this vulnerability.
CVE-2022-48354 affects Huawei devices running EMUI 12.0.0, EMUI 13.0.0, HarmonyOS 2.0, 2.1.0, 3.0.0, and 3.1.0.
Exploitation of CVE-2022-48354 can lead to crashes in the Bluetooth process on affected devices.
CVE-2022-48354 is considered to be a local vulnerability as it requires access to the device to exploit.