Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17388 | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. |
Mon, 09 Jun 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openatom
Openatom openharmony |
|
| CPEs | cpe:2.3:o:openatom:openharmony:*:*:*:*:-:*:*:* | |
| Vendors & Products |
Openatom
Openatom openharmony |
Mon, 09 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 08 Jun 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission. | |
| Title | security_access_token has an improper preservation of permissions vulnerability | |
| Weaknesses | CWE-281 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OpenHarmony
Published:
Updated: 2025-06-09T15:04:35.209Z
Reserved: 2025-03-02T07:18:52.700Z
Link: CVE-2025-27563
Updated: 2025-06-09T15:04:32.152Z
Status : Analyzed
Published: 2025-06-08T12:15:22.917
Modified: 2025-06-09T19:05:03.483
Link: CVE-2025-27563
No data.
OpenCVE Enrichment
No data.
EUVD