CVE-2022-37008
Severity CVSS v4.0:
Pending analysis
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
10/08/2022
Last modified:
15/08/2022
Description
The recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulnerability may affect system stability.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:emui:11.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:emui:11.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:emui:12.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:harmonyos:2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:magic_ui:4.0.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



