PT-2022-27665 · Unknown · Openharmony

CVE-2022-45877

·

Published

2022-12-08

·

Updated

2023-07-07

CVSS v3.1

8.3

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenHarmony versions prior to 3.1.4
Description The issue allows a PIN code to be transmitted in plain text during cross-device authentication, making it easier for attackers to perform man-in-the-middle attacks.
Recommendations For versions prior to 3.1.4, update to a version that contains a fix for this issue to prevent the PIN code from being transmitted in plain text.

Fix

Improper Authentication

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-45877

Affected Products

Openharmony