CVE-2023-42774: Liteos-A has a incorrect default permissions vulnerability
Published Nov 20, 2023
·Updated
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions.
Affected Software
1 affected component
Openatom Openharmony<=3.2.2
Event History
Nov 20, 2023
CVE Published
11:46 AM
Data Sourced
11:46 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability CVE-2023-42774?
The vulnerability CVE-2023-42774 refers to an incorrect default permissions vulnerability in OpenHarmony v3.2.2 and prior versions.
2
How can a local attacker exploit the CVE-2023-42774 vulnerability?
A local attacker can exploit the CVE-2023-42774 vulnerability to obtain confidential information through incorrect default permissions.
3
What is the severity of the CVE-2023-42774 vulnerability?
The severity of the CVE-2023-42774 vulnerability is medium, with a severity value of 6.2.
4
Which software versions are affected by the CVE-2023-42774 vulnerability?
OpenHarmony v3.2.2 and prior versions are affected by the CVE-2023-42774 vulnerability.
5
How can the CVE-2023-42774 vulnerability be fixed?
To fix the CVE-2023-42774 vulnerability, it is recommended to update to a version of OpenHarmony that is not affected.