Authentication Bypass by Primary Weakness
CVE-2022-48470
Summary
Huawei HiLink AI Life product has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.(Vulnerability ID:HWPSIRT-2022-42291) This vulnerability has been assigned a (CVE)ID:CVE-2022-48470
- HIGH
- LOCAL
- LOW
- UNCHANGED
- NONE
- NONE
- NONE
- LOW
CWE-305 - Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
References
Advisory Timeline
- Published