CVE-2022-45877

OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openharmony:openharmony:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:29

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 8.3
References () https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-12.md - Third Party Advisory () https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-12.md - Third Party Advisory
Summary
  • (es) OpenHarmony-v3.1.4 y versiones anteriores tenían una vulnerabilidad. El código PIN se transmite al dispositivo par en texto plano durante la autenticación entre dispositivos, lo que reduce la dificultad de los ataques de intermediario.

Information

Published : 2022-12-08 16:15

Updated : 2024-11-21 07:29


NVD link : CVE-2022-45877

Mitre link : CVE-2022-45877

CVE.ORG link : CVE-2022-45877


JSON object : View

Products Affected

openharmony

  • openharmony
CWE
CWE-287

Improper Authentication

CWE-319

Cleartext Transmission of Sensitive Information