CVE-2024-57955
Published: 06 February 2025
Description
Arbitrary write vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
Security Summary
CVE-2024-57955 is an arbitrary write vulnerability (CWE-787) in the Gallery module. Published on 2025-02-06, it carries a CVSS v3.1 base score of 6.1 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N) and may affect service confidentiality upon successful exploitation.
The vulnerability can be exploited by a local attacker with no privileges required, provided they can induce user interaction and leverage low attack complexity. Exploitation enables high-impact confidentiality loss and low-impact integrity modification, such as unauthorized data writes.
Huawei has issued a consumer support bulletin detailing the vulnerability and mitigation measures at https://consumer.huawei.com/en/support/bulletin/2025/2/.
Details
- CWE(s)