CVE-2024-56453
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Jan 8, 2025
Updated: Jan 13, 2025
CWE ID 120
Summary
CVE-2024-56453 is a newly identified vulnerability affecting the 3D engine module. The issue lies in the lack of verification of input parameters during glTF model loading. An attacker who successfully exploits this vulnerability may impact the system's availability. This weakness could potentially allow for denial-of-service attacks, making it a significant concern for organizations using the 3D engine. Organizations are encouraged to update their software as soon as a patch is available to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- HarmonyOS
Affected Vendors
- Huawei Technologies