CVE-2023-39402: Path Traversal
Published Aug 13, 2023
·Updated
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
Affected Software
9 affected components
Huawei Emui=11.0.1
Huawei Emui=12.0.0
Huawei Emui=12.0.1
Huawei Emui=13.0.0
Huawei Harmonyos=2.0.0
Huawei Harmonyos=2.0.1
Huawei Harmonyos=2.1.0
Huawei Harmonyos=3.0.0
Huawei Harmonyos=3.1.0
Event History
Aug 13, 2023
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-39402?
CVE-2023-39402 is a parameter verification vulnerability in the installd module that allows unauthorized read and write access to sandbox files.
2
How does CVE-2023-39402 affect Huawei Emui?
CVE-2023-39402 affects Huawei Emui versions 11.0.1, 12.0.0, 12.0.1, and 13.0.0.
3
How does CVE-2023-39402 affect Huawei HarmonyOS?
CVE-2023-39402 affects Huawei HarmonyOS versions 2.0.0, 2.0.1, 2.1.0, 3.0.0, and 3.1.0.
4
What is the severity of CVE-2023-39402?
CVE-2023-39402 has a severity rating of 9.1 (critical).
5
How can I fix CVE-2023-39402?
To fix CVE-2023-39402, it is recommended to apply the security updates provided by Huawei. Please refer to the official Huawei support bulletin for more information.