CVE-2023-44104

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 11, 2023
Updated: Oct 16, 2023
CWE ID 669

Summary

CVE-2023-44104 is a newly identified vulnerability affecting the Bluetooth module's permission control. This issue grants unauthorized broadcast permissions, potentially exposing service confidentiality. An attacker could exploit this vulnerability to broadcast malicious data or gain unauthorized access to nearby devices. The exact implications and potential impact on various Bluetooth implementations are still under investigation. Users are advised to update their Bluetooth software to the latest version with appropriate patch fixes to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • HarmonyOS
  • Huawei EMUI

Affected Vendors

  • Huawei Technologies