Improper Input Validation (CWE-20)
Vulnerability of pop-up windows belonging to no app in the VPN module of Huawei HarmonyOS 5.0.0. This vulnerability is related to improper input validation.
Successful exploitation of this vulnerability may affect service availability. The CVSS v3.1 base score is 5.5, indicating a medium severity. The attack vector is local, requiring low privileges and no user interaction. While there is no impact on confidentiality or integrity, the availability impact is high.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available. Huawei has released a security bulletin on November 7, 2024, which can be found at https://consumer.huawei.com/en/support/bulletin/2024/11/
1. Apply the patch provided by Huawei as soon as possible. 2. Limit local access to the affected systems to trusted users only. 3. Monitor for any suspicious local activities on systems running HarmonyOS 5.0.0. 4. Consider implementing additional access controls or network segmentation to reduce the risk of local attacks.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Feedly found the first article mentioning CVE-2024-51514. See article
Feedly estimated the CVSS score as MEDIUM
NVD published the first details for CVE-2024-51514
A CVSS base score of 5.3 has been assigned.
EPSS Score was set to: 0.04% (Percentile: 10%)
A CVSS base score of 5.5 has been assigned.