in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Openatom Openharmony
cpe:2.3:o:openatom:openharmony:5.0.3:*:*:*:-:*:*:*
|
— | — |
|
Openatom Openharmony
cpe:2.3:o:openatom:openharmony:5.1.0:*:*:*:-:*:*:*
|
— | — |