CVE-2023-39399: Critical severity emui 5.0 vulnerability
Published Aug 13, 2023
·Updated
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
Affected Software
9 affected components
Huawei Emui=11.0.1
Huawei Emui=12.0.0
Huawei Emui=12.0.1
Huawei Emui=13.0.0
Huawei Harmonyos=2.0.0
Huawei Harmonyos=2.0.1
Huawei Harmonyos=2.1.0
Huawei Harmonyos=3.0.0
Huawei Harmonyos=3.1.0
Event History
Aug 13, 2023
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-39399?
CVE-2023-39399 is a parameter verification vulnerability in the installd module.
2
What is the severity of CVE-2023-39399?
CVE-2023-39399 has a severity rating of 9.1 (Critical).
3
Which software versions are affected by CVE-2023-39399?
CVE-2023-39399 affects Huawei Emui versions 11.0.1, 12.0.0, 12.0.1, 13.0.0, Huawei Harmonyos versions 2.0.0, 2.0.1, 2.1.0, 3.0.0, and 3.1.0.
4
How can CVE-2023-39399 be exploited?
Successful exploitation of CVE-2023-39399 may cause sandbox files to be read and written without authorization.
5
How can I fix CVE-2023-39399?
To fix CVE-2023-39399, it is recommended to apply the security patches provided by Huawei.