CVE-2022-36423

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
09/09/2022
Last modified:
09/09/2024

Description

OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openharmony:openharmony:*:*:*:*:long_term_support:*:*:* 1.1.0 (including) 1.1.5 (including)
cpe:2.3:a:openharmony:openharmony:*:*:*:*:long_term_support:*:*:* 3.0 (including) 3.0.5 (including)
cpe:2.3:o:openatom:openharmony:*:*:*:*:-:*:*:* 3.1 (including) 3.1.2 (including)