« Volver al listado

CVE-2023-52366

Estado: AnalizadaAlta (7.5)—

Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-52366",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-52366",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-22T17:52:49.069888Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@huawei.com",
      "affectedData": [
        {
          "vendor": "Huawei",
          "product": "HarmonyOS",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.0"
            },
            {
              "status": "affected",
              "version": "3.1.0"
            },
            {
              "status": "affected",
              "version": "3.0.0"
            },
            {
              "status": "affected",
              "version": "2.0.0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Huawei",
          "product": "EMUI",
          "versions": [
            {
              "status": "affected",
              "version": "13.0.0"
            },
            {
              "status": "affected",
              "version": "12.0.0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:huawei:harmonyos:4.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "huawei",
          "product": "harmonyos",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:huawei:harmonyos:3.1.0:*:*:*:*:*:*:*"
          ],
          "vendor": "huawei",
          "product": "harmonyos",
          "versions": [
            {
              "status": "affected",
              "version": "3.1.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:huawei:harmonyos:3.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "huawei",
          "product": "harmonyos",
          "versions": [
            {
              "status": "affected",
              "version": "3.0.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:huawei:harmonyos:2.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "huawei",
          "product": "harmonyos",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:huawei:emui:13.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "huawei",
          "product": "emui",
          "versions": [
            {
              "status": "affected",
              "version": "13.0.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:huawei:emui:12.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "huawei",
          "product": "emui",
          "versions": [
            {
              "status": "affected",
              "version": "12.0.0"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-02-18T04:15:07.560",
  "references": [
    {
      "url": "https://consumer.huawei.com/en/support/bulletin/2024/2/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@huawei.com"
    },
    {
      "url": "https://consumer.huawei.com/en/support/bulletin/2024/2/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://device.harmonyos.com/cn/docs/security/update/security-bulletins-202402-0000001834855405",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@huawei.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de lectura fuera de los límites en el módulo de reconocimiento de actividad inteligente. La explotación exitosa de esta vulnerabilidad puede provocar que las funciones funcionen de manera anormal."
    }
  ],
  "lastModified": "2026-06-17T06:42:35.290",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:huawei:emui:12.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A974CA73-84E8-480B-BB4C-4A81D0C985B2"
            },
            {
              "criteria": "cpe:2.3:o:huawei:emui:13.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "353AEAF2-AF46-4835-93E1-4F942D5E2810"
            },
            {
              "criteria": "cpe:2.3:o:huawei:harmonyos:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20112231-B840-44D3-A061-B9B9F80EE378"
            },
            {
              "criteria": "cpe:2.3:o:huawei:harmonyos:3.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB3751C1-7729-41D3-AE50-80B5AF601135"
            },
            {
              "criteria": "cpe:2.3:o:huawei:harmonyos:3.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D81C4EF-7CAF-4E60-91A4-8CF7B95B2B54"
            },
            {
              "criteria": "cpe:2.3:o:huawei:harmonyos:4.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8198CDB2-4BC5-411A-8736-615A531FC545"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@huawei.com"
}