CVE-2023-43612
in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.02%
- CWE
- CWE-281
- Published
- 2023-11-20
- Last modified
- 2026-03-13
Affected products
- OpenHarmony OpenHarmony
Weakness type
Related vulnerabilities
- CVE-2023-48240 — XWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgery
- CVE-2020-8913 — Local arbitrary code execution in splitinstall in Android's Play Core
- CVE-2025-7346 — Any unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create
- CVE-2025-34298 — Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation
- CVE-2025-24337 — WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.
- CVE-2023-0975 — A vulnerability exists in Trellix Agent for Windows version 5.7.8 and earlier, that allows local users, during install/
- CVE-2021-43816 — Improper Preservation of Permissions in containerd
- CVE-2026-23556 — oxenstored keeps quota related use counts across domain destruction