PT-2022-27665 · Unknown · Openharmony
Published
2022-12-08
·
Updated
2023-07-07
·
CVE-2022-45877
CVSS v3.1
8.3
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
OpenHarmony versions prior to 3.1.4
Description
The issue allows a PIN code to be transmitted in plain text during cross-device authentication, making it easier for attackers to perform man-in-the-middle attacks.
Recommendations
For versions prior to 3.1.4, update to a version that contains a fix for this issue to prevent the PIN code from being transmitted in plain text.
Fix
Improper Authentication
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openharmony