Cyber Posture

CVE-2024-57956

Low

Published: 06 February 2025

Published
06 February 2025
Modified
17 March 2025
KEV Added
Patch
CVSS Score 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
EPSS Score 0.0005 15.1th percentile
Risk Priority 6 60% EPSS · 20% KEV · 20% CVSS

Description

Out-of-bounds read vulnerability in the interpreter string module Impact: Successful exploitation of this vulnerability may affect availability.

Security Summary

CVE-2024-57956 is an out-of-bounds read vulnerability (CWE-680, CWE-125) in the interpreter string module. Published on 2025-02-06, it carries a CVSS v3.1 base score of 2.8 (AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L) and has been disclosed in a Huawei consumer security bulletin.

Exploitation requires local access, low attack complexity, low privileges, and user interaction from the target user. A successful attack can affect system availability with low impact, such as causing a partial denial of service.

Huawei's security bulletin at https://consumer.huawei.com/en/support/bulletin/2025/2/ provides details on the vulnerability and recommended mitigations or patches.

Details

CWE(s)
CWE-680CWE-125

Affected Products

huawei
harmonyos
5.0.0

References