« Volver al listado

Openharmony

Openharmony: vulnerabilidades y CVE

Openharmony tiene 28 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE28
Últimos 12 meses10
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-33565Baja (3.3)0.10%—19 may 2026
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-28751Baja (3.3)0.13%—19 may 2026
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-28733Media (6.5)0.15%—19 may 2026
in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.
CVE-2026-27781Baja (3.3)0.13%—19 may 2026
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-27766Media (5.5)0.11%—19 may 2026
in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.
CVE-2026-27648Alta (8.8)0.73%—19 may 2026
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
CVE-2026-25850Media (5.5)0.13%—19 may 2026
in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak
CVE-2026-25781Alta (8.4)0.15%—19 may 2026
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.
CVE-2026-25110Baja (3.3)0.12%—19 may 2026
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.
CVE-2026-24792Alta (8.1)0.43%—19 may 2026
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
CVE-2022-45126Alta (7.8)0.18%—9 ene 2023
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kernel stack are copied to user space…
CVE-2022-43662Alta (7.8)0.18%—9 ene 2023
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kernel stack are copied to user space…
CVE-2022-45877Media (5.3)0.17%—8 dic 2022
OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.
CVE-2022-45118Media (5.5)0.18%—8 dic 2022
OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events with personal data, but the permission is not set. Malicious apps could listen to public events and…
CVE-2022-44455Alta (7.8)0.22%—8 dic 2022
The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. An unprivileged malicious application…
CVE-2022-41802Baja (3.3)0.19%—8 dic 2022
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGetres. 4 bytes padding data from kernel stack are copied to user space…
CVE-2022-43495Alta (7.5)0.66%—3 nov 2022
OpenHarmony-v3.1.2 and prior versions had a DOS vulnerability in distributedhardware_device_manager when joining a network. Network attakcers can send an abonormal packet when joining a network, cause a nullptr…
CVE-2022-43451Media (6.5)0.19%—3 nov 2022
OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape application sandbox.If chained with other…
CVE-2022-43449Media (5.5)0.18%—3 nov 2022
OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can install an malicious application on the device and reveal any file from the filesystem that is…
CVE-2022-42488Alta (7.8)0.18%—14 oct 2022
OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root…
CVE-2022-42464Alta (7.8)0.19%—14 oct 2022
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged…
CVE-2022-42463Alta (8.8)0.30%—14 oct 2022
OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch attacks on distributed networks by…
CVE-2022-41686Media (4.4)0.32%—14 oct 2022
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The…
CVE-2022-38701Baja (3.3)0.20%—9 sept 2022
OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow and get network sensitive information.
CVE-2022-38700Alta (8.8)0.37%—9 sept 2022
OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.
CVE-2022-38081Media (5.5)0.19%—9 sept 2022
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed permission control.To take advantage of this weakness, attackers need another vulnerability to…
CVE-2022-38064Media (5.5)0.18%—9 sept 2022
OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. Local attackers can bypass permission control and get sensitive information.
CVE-2022-36423Alta (7.4)0.33%—9 sept 2022
OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1210 Exploitation of Remote Services2
  3. T1068 Exploitation for Privilege Escalation1
  4. T1499.004 Application or System Exploitation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.