← back
CVE-2024-57957mediumCWE-657

CVE-2024-57957

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.6epss 0.3%
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
In short

The UI framework doesn't properly control what information gets logged, potentially exposing sensitive data in log files that shouldn't be there. This can allow attackers to access confidential information if they gain access to logs.

Technical detail

CWE-657 (Improper Control of Dynamically-Managed Code Resources) manifests in the UI framework module where sensitive information is inadequately sanitized before being written to logs. Exploitation requires access to log files; successful attacks may lead to unauthorized disclosure of confidential data affecting service confidentiality.

Summary generated and translated by AI from the official description.
Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Huawei · HarmonyOS