CVE-2023-37242: Critical severity Huawei Emui vulnerability
Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37242?
The severity of CVE-2023-37242 is critical with a score of 9.8.
How can attackers exploit CVE-2023-37242?
Attackers may exploit CVE-2023-37242 to rewrite the non-volatile random-access memory (NVRAM) or facilitate the exploitation of other vulnerabilities.
Which software versions are affected by CVE-2023-37242?
Huawei Emui versions 12.0.0 and 13.0.0, as well as Huawei Harmonyos versions 2.0 and 3.0.0, are affected by CVE-2023-37242.
Are there any official references for CVE-2023-37242?
Yes, you can find official references for CVE-2023-37242 at the following links: [Consumer Huawei](https://consumer.huawei.com/en/support/bulletin/2023/7/) and [HarmonyOS Device](https://device.harmonyos.com/en/docs/security/update/security-bulletins-202307-0000001587168858).
What is the CWE ID for CVE-2023-37242?
The CWE ID for CVE-2023-37242 is 639.