7.3
CVE-2023-23432
- EPSS 0.03%
- Veröffentlicht 29.12.2023 02:15:44
- Zuletzt bearbeitet 21.11.2024 07:46:11
- Quelle 3836d913-7555-4dd0-a509-f5667f
- CVE-Watchlists
- Unerledigt
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hihonor ≫ Nth-an00 Firmware Version < 7.0.0.157
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.077 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
| 3836d913-7555-4dd0-a509-f5667fdf5fe4 | 7.3 | 2.5 | 4.7 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.