First published: Thu Jul 06 2023(Updated: )
Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Emui | =12.0.0 | |
Huawei Emui | =13.0.0 | |
Huawei Harmonyos | =2.0 | |
Huawei Harmonyos | =3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-37242 is critical with a score of 9.8.
Attackers may exploit CVE-2023-37242 to rewrite the non-volatile random-access memory (NVRAM) or facilitate the exploitation of other vulnerabilities.
Huawei Emui versions 12.0.0 and 13.0.0, as well as Huawei Harmonyos versions 2.0 and 3.0.0, are affected by CVE-2023-37242.
Yes, you can find official references for CVE-2023-37242 at the following links: [Consumer Huawei](https://consumer.huawei.com/en/support/bulletin/2023/7/) and [HarmonyOS Device](https://device.harmonyos.com/en/docs/security/update/security-bulletins-202307-0000001587168858).
The CWE ID for CVE-2023-37242 is 639.