Lucene search

K
cve[email protected]CVE-2015-7842
HistoryOct 10, 2017 - 1:30 a.m.

CVE-2015-7842

2017-10-1001:30:20
CWE-275
web.nvd.nist.gov
28
huawei
fusionserver
rack servers
rh2288 v3
security
vulnerability
software
remote
authenticated
operators
permissions

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

49.9%

Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with software before V100R003C00SPC602, RH2288A V2 with software before V100R002C00SPC701, RH1288A V2 with software before V100R002C00SPC502, RH8100 V3 with software before V100R003C00SPC110, CH222 V3 with software before V100R001C00SPC161, CH220 V3 with software before V100R001C00SPC161, and CH121 V3 with software before V100R001C00SPC161 allow remote authenticated operators to change server information by leveraging failure to verify user permissions.

Affected configurations

NVD
Node
huaweirh2288_v3_firmwareRangev100r003c00
AND
huaweirh2288_v3Match-
Node
huaweirh2288h_v3_firmwareRangev100r003c00
AND
huaweirh2288h_v3Match-
Node
huaweixh628_v3_firmwareRangev100r003c00
AND
huaweixh628_v3Match-
Node
huaweirh1288_v3_firmwareRangev100r003c00spc100
AND
huaweirh1288_v3Match-
Node
huaweirh2288a_v2_firmwareRangev100r002c00
AND
huaweirh2288a_v2Match-
Node
huaweirh1288a_v2_firmwareRangev100r002c00
AND
huaweirh1288a_v2Match-
Node
huaweirh8100_v3_firmwareRangev100r003c00
AND
huaweirh8100_v3Match-
Node
huaweich222_v3_firmwareRangev100r001c00
AND
huaweich222_v3Match-
Node
huaweich220_v3_firmwareRangev100r001c00
AND
huaweich220_v3Match-
Node
huaweich121_v3_firmwareRangev100r001c00
AND
huaweich121_v3Match-

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

49.9%

Related for CVE-2015-7842