CVE-2024-29074: Telephony has an improper input validation vulnerability
Published Apr 2, 2024
·Updated
in OpenHarmony v3.2.4 and prior versions allow a local attacker arbitrary code execution in any apps through improper input.
Affected Software
1 affected component
Openatom Openharmony<=3.2.4
Event History
Apr 2, 2024
CVE Published
via MITRE·06:22 AM
Data Sourced
via MITRE·06:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-29074?
CVE-2024-29074 is classified with a high severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2024-29074?
To fix CVE-2024-29074, upgrade to OpenHarmony version 3.2.5 or later.
3
Who is affected by CVE-2024-29074?
CVE-2024-29074 affects all applications running on OpenHarmony versions 3.2.4 and earlier.
4
What type of vulnerability is CVE-2024-29074?
CVE-2024-29074 is a local vulnerability that allows arbitrary code execution through improper input handling.
5
Can CVE-2024-29074 be exploited remotely?
No, CVE-2024-29074 requires local access to exploit the vulnerability.