CVE-2023-24465 MEDIUM

CVE-2023-24465: Communication Wi-Fi  subsystem has a null pointer reference vulnerability when receving external data.

Vendor Openharmony
Product OpenHarmony
Weakness CWE-20 · Input validation
Published March 10, 2023
Last update March 4, 2025

CVSS base score

5.5/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause the current application to crash.

Key dates

02Disclosure timeline

March 10, 2023 CVE published
March 4, 2025 Record updated