First published: Sun Aug 13 2023(Updated: )
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
Credit: psirt@huawei.com psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Emui | =11.0.1 | |
Huawei Emui | =12.0.0 | |
Huawei Emui | =12.0.1 | |
Huawei Emui | =13.0.0 | |
Huawei Harmonyos | =2.0.0 | |
Huawei Harmonyos | =2.0.1 | |
Huawei Harmonyos | =2.1.0 | |
Huawei Harmonyos | =3.0.0 | |
Huawei Harmonyos | =3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-39401.
The severity of CVE-2023-39401 is critical.
The affected software versions are Huawei Emui 11.0.1, Huawei Emui 12.0.0, Huawei Emui 12.0.1, Huawei Emui 13.0.0, Huawei Harmonyos 2.0.0, Huawei Harmonyos 2.0.1, Huawei Harmonyos 2.1.0, Huawei Harmonyos 3.0.0, and Huawei Harmonyos 3.1.0.
CVE-2023-39401 is a parameter verification vulnerability in the installd module that allows unauthorized reading and writing of sandbox files.
To fix the CVE-2023-39401 vulnerability, it is recommended to apply the security patches provided by Huawei.