OpenHarmony is an open-source operating system project that has gained prominence in the embedded and mobile device landscape, supported by a broad ecosystem of manufacturers and device deployments. Its vulnerability profile centers on a single product line but recurs through foundational weakness classes including improper authentication, out-of-bounds writes, buffer overflows, authentication bypass flaws, and default permission issues that reflect the memory-safety and access-control complexity inherent to an OS kernel and middleware stack. Defenders should monitor this vendor's advisories for authentication and memory-safety patterns, particularly across connected and embedded deployments; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by OpenHarmony over time
Of all the CVEs published by OpenHarmony as a CNA, 10.2% affect products that OpenHarmony develops as a vendor.
Of all the CVEs published that affect products developed by OpenHarmony, 100.0% are self-published by OpenHarmony as a CNA.
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-42463HIGH OpenHarmony-v3.1.2 and prior versions have an authenication bypass vulnerability in a callback handler function of Softbus_server in communication subsystem. Attackers can launch a | Oct 14, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-38700HIGH OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission control and get control of camera service. | Sep 9, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-43662HIGH Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysTimerGettime. 4 bytes padding data from kern | Jan 9, 2023 | 7.8 | 26 | NO | NO |
CVE-2022-45126HIGH Kernel subsystem within OpenHarmony-v3.1.4 and prior versions in kernel_liteos_a has a kernel stack overflow vulnerability when call SysClockGettime. 4 bytes padding data from kern | Jan 9, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-42488HIGH OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device cou | Oct 14, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-42464HIGH OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have a Kernel memory pool override vulnerability in /dev/mmz_userdev device driver. The impact depends on the privil | Oct 14, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-44455HIGH The appspawn and nwebspawn services within OpenHarmony-v3.1.2 and prior versions were found to be vulnerable to buffer overflow vulnerability due to insufficient input validation. | Dec 8, 2022 | 7.8 | 24 | NO | NO |
CVE-2022-43495HIGH OpenHarmony-v3.1.2 and prior versions had a DOS vulnerability in distributedhardware_device_manager when joining a network. Network attakcers can send an abonormal packet when join | Nov 3, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-36423HIGH OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can l | Sep 9, 2022 | 7.4 | 24 | NO | NO |
CVE-2022-43451MEDIUM OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. Local attackers can create arbitrary directories or escape ap | Nov 3, 2022 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by OpenHarmony.
Media articles that mention a CVE ID that affects a product developed by OpenHarmony — matched by CVE ID, not by vendor name.