« Back to list

CVE-2023-23431

Status: ModifiedHigh (7.1)—

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2023-23431",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-23431",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-09T17:43:37.282419Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "3836d913-7555-4dd0-a509-f5667fdf5fe4",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 2.5
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "3836d913-7555-4dd0-a509-f5667fdf5fe4",
      "affectedData": [
        {
          "vendor": "Honor",
          "product": "NTH-AN00",
          "versions": [
            {
              "status": "affected",
              "version": " 7.0.0.138",
              "lessThan": " 7.0.0.157",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-29T02:15:43.803",
  "references": [
    {
      "url": "https://www.hihonor.com/global/security/cve-2023-23431/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "3836d913-7555-4dd0-a509-f5667fdf5fe4"
    },
    {
      "url": "https://www.hihonor.com/global/security/cve-2023-23431/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "3836d913-7555-4dd0-a509-f5667fdf5fe4",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-347"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nSome Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.\n\n"
    },
    {
      "lang": "es",
      "value": "Algunos productos Honor se ven afectados por una vulnerabilidad en la administración de firmas; una explotación exitosa podría causar que el archivo del sistema falsificado sobrescriba el archivo del sistema correcto."
    }
  ],
  "lastModified": "2026-06-17T05:37:07.133",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hihonor:nth-an00_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80776BEE-9BF5-4B6A-9F79-6BFF69B058B7",
              "versionEndExcluding": "7.0.0.157"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hihonor:nth-an00:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A086FF80-9CB7-4590-9025-B8757B64E358"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "3836d913-7555-4dd0-a509-f5667fdf5fe4"
}