Cyber Posture

CVE-2024-57955

Medium

Published: 06 February 2025

Published
06 February 2025
Modified
26 September 2025
KEV Added
Patch
CVSS Score 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
EPSS Score 0.0010 28.1th percentile
Risk Priority 12 60% EPSS · 20% KEV · 20% CVSS

Description

Arbitrary write vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Security Summary

CVE-2024-57955 is an arbitrary write vulnerability (CWE-787) in the Gallery module. Published on 2025-02-06, it carries a CVSS v3.1 base score of 6.1 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N) and may affect service confidentiality upon successful exploitation.

The vulnerability can be exploited by a local attacker with no privileges required, provided they can induce user interaction and leverage low attack complexity. Exploitation enables high-impact confidentiality loss and low-impact integrity modification, such as unauthorized data writes.

Huawei has issued a consumer support bulletin detailing the vulnerability and mitigation measures at https://consumer.huawei.com/en/support/bulletin/2025/2/.

Details

CWE(s)
CWE-787NVD-CWE-noinfo

Affected Products

huawei
harmonyos
5.0.0

References