HIGH
The LBS module has a vulnerability in geofencing API access
Published Nov 9, 2022
7.5
HIGHCVSS 3.1
EPSS 0.43%
Description
The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.
Affected products
-
- Version 11.0.1StatusaffectedConstraints-
- Version 12.0.0StatusaffectedConstraints-
- Version 12.0.1StatusaffectedConstraints-
- Version
-
- Version 2.0StatusaffectedConstraints-
- Version 2.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://consumer.huawei.com/en/support/bulletin/2022/11/ Vendor Advisory
- https://device.harmonyos.com/en/docs/security/update/security-bulletins-phones-202211-0000001441016433 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://consumer.huawei.com/en/support/bulletin/2022/11/ | Vendor Advisory | |
| https://device.harmonyos.com/en/docs/security/update/security-bulletins-phones-202211-0000001441016433 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner huawei
Published Nov 9, 2022
Updated May 1, 2025
Reserved Nov 1, 2022
Link CVE-2022-44549
CISA Vulnrichment
Updated May 1, 2025