Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

OpenHarmony

First CVE: Sep 9, 2022Active for: 4 yearsTotal CVEs: 18
35.5
VTI Score
Medium

OpenHarmony is an open-source operating system project that has gained prominence in the embedded and mobile device landscape, supported by a broad ecosystem of manufacturers and device deployments. Its vulnerability profile centers on a single product line but recurs through foundational weakness classes including improper authentication, out-of-bounds writes, buffer overflows, authentication bypass flaws, and default permission issues that reflect the memory-safety and access-control complexity inherent to an OS kernel and middleware stack. Defenders should monitor this vendor's advisories for authentication and memory-safety patterns, particularly across connected and embedded deployments; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
9.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by OpenHarmony over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 9, 2022
3 years ago
Most Recent CVE
Jan 9, 2023
1,292 days ago

Self-Reporting Analysis

Of all the CVEs published by OpenHarmony as a CNA, 10.2% affect products that OpenHarmony develops as a vendor.

10.2%
89.8%
Self-reported: 18 (10.2%)
Third-party: 159 (89.8%)

Of all the CVEs published that affect products developed by OpenHarmony, 100.0% are self-published by OpenHarmony as a CNA.

100.0%
Self-published: 18 (100.0%)
Other CNAs: 0 (0.0%)

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-42463HIGH
OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch a
Oct 14, 20228.827NONO
CVE-2022-38700HIGH
OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service.
Sep 9, 20228.827NONO
CVE-2022-43662HIGH
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kern
Jan 9, 20237.826NONO
CVE-2022-45126HIGH
Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kern
Jan 9, 20237.825NONO
CVE-2022-42488HIGH
OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device cou
Oct 14, 20227.825NONO
CVE-2022-42464HIGH
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privil
Oct 14, 20227.825NONO
CVE-2022-44455HIGH
The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation.
Dec 8, 20227.824NONO
CVE-2022-43495HIGH
OpenHarmony-v3.1.2 and prior versions had a DOS vulnerability in distributedhardware_device_manager when joining a network. Network attakcers can send an abonormal packet when join
Nov 3, 20227.524NONO
CVE-2022-36423HIGH
OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can l
Sep 9, 20227.424NONO
CVE-2022-43451MEDIUM
OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape ap
Nov 3, 20226.522NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
11%
39%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local13 (72.2%)
Network1 (5.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (22.2%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None18 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low13 (72.2%)
High0 (0.0%)
None5 (27.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by OpenHarmony.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by OpenHarmony — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For OpenHarmony's Products

View all 1 CNAs →

Top CWEs