CVE-2024-56453

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 8, 2025
Updated: Jan 13, 2025
CWE ID 120

Summary

CVE-2024-56453 is a newly identified vulnerability affecting the 3D engine module. The issue lies in the lack of verification of input parameters during glTF model loading. An attacker who successfully exploits this vulnerability may impact the system's availability. This weakness could potentially allow for denial-of-service attacks, making it a significant concern for organizations using the 3D engine. Organizations are encouraged to update their software as soon as a patch is available to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • HarmonyOS

Affected Vendors

  • Huawei Technologies