// For flags

CVE-2022-36423

Incorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.

Severity Score

7.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.

OpenHarmony versiones v3.1.2 y anteriores, presentan una configuración incorrecta de la biblioteca cJSON, que conlleva a una vulnerabilidad de desbordamiento de pila durante el análisis recursivo. Los atacantes de la LAN pueden conllevar a un ataque DoS a todos los dispositivos de la red

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-09-04 CVE Reserved
  • 2022-09-09 CVE Published
  • 2024-09-17 CVE Updated
  • 2025-06-04 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-16: Configuration
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Openharmony
Search vendor "Openharmony"
Openharmony
Search vendor "Openharmony" for product "Openharmony"
>= 1.1.0 <= 1.1.5
Search vendor "Openharmony" for product "Openharmony" and version " >= 1.1.0 <= 1.1.5"
long_term_support
Affected
Openharmony
Search vendor "Openharmony"
Openharmony
Search vendor "Openharmony" for product "Openharmony"
>= 3.0 <= 3.0.5
Search vendor "Openharmony" for product "Openharmony" and version " >= 3.0 <= 3.0.5"
long_term_support
Affected
Openharmony
Search vendor "Openharmony"
Openharmony
Search vendor "Openharmony" for product "Openharmony"
>= 3.1 <= 3.1.2
Search vendor "Openharmony" for product "Openharmony" and version " >= 3.1 <= 3.1.2"
-
Affected