PT-2024-26926 · Unknown · Openharmony

Published

2024-07-02

·

Updated

2024-09-09

·

CVE-2024-36243

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenHarmony versions prior to 4.0.0 OpenHarmony version 4.0.0
Description The issue allows a remote attacker to execute arbitrary code in pre-installed apps through out-of-bounds read and write.
Recommendations For OpenHarmony versions prior to 4.0.0, update to version 4.0.0 or later. For OpenHarmony version 4.0.0, no specific fix is provided beyond this version, so consider this version as the baseline for security.

Fix

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2024-36243

Affected Products

Openharmony