CVE-2024-56452
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Jan 8, 2025
Updated: Jan 13, 2025
CWE ID 120
Summary
CVE-2024-56452 is a newly identified vulnerability affecting the 3D engine module. The weakness lies in the lack of verification of input parameters during the glTF model loading process. An attacker who successfully exploits this flaw can cause denial-of-service issues, impacting system availability. The exact extent and potential consequences of this vulnerability remain to be determined. It is recommended that users apply the necessary patches and updates as soon as they become available to mitigate potential risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- HarmonyOS
Affected Vendors
- Huawei Technologies