CVE-2025-68967
Huawei Harmonyos 6.0.0
Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:LSummary
CVE-2025-68967 is a medium-severity an unspecified weakness vulnerability in Huawei Harmonyos. Its CVSS base score is 5.7 (Medium).
Operationally, ranked at the 1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and AC-6 (Least Privilege) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-2565
Vulnerability Data
Vulnerability of improper permission control in the print module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Insufficient information to map techniques.CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces access permissions on the print module to block unauthorized actions that could compromise confidentiality.
Limits privileges assigned to the print module so that improper or excessive permissions cannot be exploited.
Enforces information flow rules that can restrict unauthorized data exposure originating from the print module.