CVE-2021-40006
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to potentially access sensitive information due to flaws in the security algorithms used by HarmonyOS. To exploit this, the attacker would need to find a way to interact with the affected system, which could compromise the confidentiality of the data.
Technical Description
Vulnerability of design defects in the security algorithm component. Successful exploitation of this vulnerability may affect confidentiality.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Jan 10, 2022
about 4 years ago
Last Modified
Feb 24, 2026
about 1 month ago
Vendor
huawei
Product
harmonyos
Related Vulnerabilities
This vulnerability allows an attacker to disrupt the security management of Huawei devices running HarmonyOS, potentially causing the system to become unavailable. To exploit this issue, the attacker must be able to trigger a race condition, which occurs when two processes try to access the same resource at the same time.
This vulnerability allows an attacker to disrupt the permission management system on HarmonyOS, potentially causing the service to become unavailable. To exploit this, the attacker needs to take advantage of a timing issue in how permissions are handled, which could lead to service interruptions.
This vulnerability allows an attacker to potentially access sensitive information from the email application due to a failure in properly verifying user actions. To exploit this, the attacker would need to trick the application into accepting malicious inputs, which could compromise the confidentiality of user data.
This vulnerability allows an attacker to potentially disrupt the operation of HarmonyOS by exploiting an issue with uninitialized pointers in the scanning module. Successful exploitation requires the attacker to have access to the affected system, which could lead to service interruptions or crashes.
This vulnerability allows an attacker to crash the scanning module of HarmonyOS, potentially making the system unavailable. To exploit this, the attacker needs to send specially crafted input to the module, which could happen if the device is connected to a malicious network or application.