Lucene search

K
cve[email protected]CVE-2018-7941
HistoryMay 10, 2018 - 2:29 p.m.

CVE-2018-7941

2018-05-1014:29:00
CWE-287
web.nvd.nist.gov
32
huawei
ibmc
v200r002c60
authentication bypass
vulnerability
privilege elevation
nvd

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.8 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.7%

Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due to improper validation of the upload authority, successful exploit may cause privilege elevation.

Affected configurations

NVD
Node
huaweich121_v3_firmwareMatch100r001c00
AND
huaweich121_v3Match-
Node
huaweich121l_v3_firmwareMatch100r001c00
AND
huaweich121l_v3Match-
Node
huaweich140_v3_firmwareMatch100r001c00
AND
huaweich140_v3Match-
Node
huaweich140l_v3_firmwareMatch100r001c00
AND
huaweich140l_v3Match-
Node
huaweich220_v3_firmwareMatch100r001c00
AND
huaweich220_v3Match-
Node
huaweich222_v3_firmwareMatch100r001c00
AND
huaweich222_v3Match-
Node
huaweich242_v3_firmwareMatch100r001c00
AND
huaweich242_v3Match-
Node
huaweirh1288_v3_firmwareMatch100r003c00
AND
huaweirh1288_v3Match-
Node
huaweirh2288_v3_firmwareMatch100r003c00
AND
huaweirh2288_v3Match-
Node
huaweirh2288h_v3_firmwareMatch100r003c00
AND
huaweirh2288h_v3Match-
Node
huaweixh310_v3_firmwareMatch100r003c00
AND
huaweixh310_v3Match-
Node
huaweixh321_v3_firmwareMatch100r003c00
AND
huaweixh321_v3Match-
Node
huaweixh620_v3_firmwareMatch100r003c00
AND
huaweixh620_v3Match-
Node
huaweich121_v5_firmwareMatch100r001c00
AND
huaweich121_v5Match-
Node
huaweich121l_v5_firmwareMatch100r001c00
AND
huaweich121l_v5Match-
Node
huaweich242_v5_firmwareMatch100r001c00
AND
huaweich242_v5Match-
Node
huawei1288h_v5_firmwareMatch100r005c00
AND
huawei1288h_v5Match-
Node
huawei2288h_v5_firmwareMatch100r005c00
AND
huawei2288h_v5Match-
Node
huawei2488_v5_firmwareMatch100r005c00
AND
huawei2488_v5Match-
Node
huaweixh321_v5_firmwareMatch100r005c00
AND
huaweixh321_v5Match-

CNA Affected

[
  {
    "product": "iBMC",
    "vendor": "Huawei Technologies Co., Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "V200R002C60"
      }
    ]
  }
]

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.8 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.7%

Related for CVE-2018-7941