SB2023012429 - Multiple vulnerabilities in OpenHarmony
Published: January 24, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Authentication Bypass by Capture-replay (CVE-ID: CVE-2023-0036)
The vulnerability allows a local user to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests in the platform_callback_stub function in the misc subsystem. A local user can bypass authentication process and obtain sensitive information.
2) Authentication Bypass by Capture-replay (CVE-ID: CVE-2023-0035)
The vulnerability allows a local user to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests in the softbus_client_stub function in the communication subsystem. A local user can bypass authentication process and obtain sensitive information.
Remediation
Install update from vendor's website.