CVE-2024-56455
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Jan 8, 2025
Updated: Jan 13, 2025
CWE ID 120
Summary
CVE-2024-56455 is a newly identified vulnerability affecting the 3D engine module. The issue lies in the failure to verify input parameters during the glTF model loading process. An attacker can potentially exploit this vulnerability, leading to potential availability issues. This vulnerability poses a risk if maliciously crafted glTF models are loaded into the system. To mitigate this risk, it is recommended that input parameters be thoroughly verified before loading any glTF models into the 3D engine module.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- HarmonyOS
Affected Vendors
- Huawei Technologies