First published: Thu Jul 25 2024(Updated: )
Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMUI 5.0 | =12.0.0 | |
EMUI 5.0 | =13.0.0 | |
EMUI 5.0 | =14.0.0 | |
HarmonyOS | =2.0.0 | |
HarmonyOS | =2.1.0 | |
HarmonyOS | =3.0.0 | |
HarmonyOS | =3.1.0 | |
HarmonyOS | =4.0.0 | |
HarmonyOS | =4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39673 is considered a high-severity vulnerability due to its potential impact on service confidentiality.
To fix CVE-2024-39673, update affected Huawei software to the latest version that addresses this vulnerability.
CVE-2024-39673 affects Huawei Emui versions 12.0.0, 13.0.0, 14.0.0 and HarmonyOS versions 2.0.0 through 4.2.0.
Exploitation of CVE-2024-39673 may compromise the confidentiality of services within the affected software.
Yes, CVE-2024-39673 is specific to devices running affected versions of Huawei Emui and HarmonyOS.