Vulnerability Description
Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Emui | 12.0.0 |
| Huawei | Harmonyos | 2.0.0 |
Related Weaknesses (CWE)
References
- https://consumer.huawei.com/en/support/bulletin/2023/7/Vendor Advisory
- https://device.harmonyos.com/en/docs/security/update/security-bulletins-202307-0Vendor Advisory
- https://consumer.huawei.com/en/support/bulletin/2023/7/Vendor Advisory
- https://device.harmonyos.com/en/docs/security/update/security-bulletins-202307-0Vendor Advisory
FAQ
What is CVE-2022-48518?
CVE-2022-48518 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause maliciou...
How severe is CVE-2022-48518?
CVE-2022-48518 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-48518?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Emui, Huawei Harmonyos.