PT-2022-27665 · Unknown · Openharmony

Published

2022-12-08

·

Updated

2023-07-07

·

CVE-2022-45877

CVSS v3.1

8.3

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OpenHarmony versions prior to 3.1.4
Description The issue allows a PIN code to be transmitted in plain text during cross-device authentication, making it easier for attackers to perform man-in-the-middle attacks.
Recommendations For versions prior to 3.1.4, update to a version that contains a fix for this issue to prevent the PIN code from being transmitted in plain text.

Fix

Improper Authentication

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-45877

Affected Products

Openharmony