There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerability to get some sensitive information and high-level users’ privilege.
[
{
"product": "1288H V5; 2288H V5; 2488 V5 ; CH121 V3; CH121L V3; CH121L V5 ; CH121 V5 ; CH140 V3; CH140L V3; CH220 V3; CH222 V3; CH242 V3; CH242 V5 ; RH1288 V3; RH2288 V3; RH2288H V3; XH310 V3; XH321 V3; XH321 V5; XH620 V3",
"vendor": "Huawei Technologies Co., Ltd.",
"versions": [
{
"status": "affected",
"version": "1288H V5 V100R005C00"
},
{
"status": "affected",
"version": "2288H V5 V100R005C00"
},
{
"status": "affected",
"version": "2488 V5 V100R005C00"
},
{
"status": "affected",
"version": "CH121 V3 V100R001C00"
},
{
"status": "affected",
"version": "CH121L V3 V100R001C00"
},
{
"status": "affected",
"version": "CH121L V5 V100R001C00"
},
{
"status": "affected",
"version": "CH121 V5 V100R001C00"
},
{
"status": "affected",
"version": "CH140 V3 V100R001C00"
},
{
"status": "affected",
"version": "CH140L V3 V100R001C00"
},
{
"status": "affected",
"version": "CH220 V3 V100R001C00"
},
{
"status": "affected",
"version": "CH222 V3 V100R001C00"
},
{
"status": "affected",
"version": "CH242 V3 V100R001C00"
},
{
"status": "affected",
"version": "CH242 V5 V100R001C00"
},
{
"status": "affected",
"version": "RH1288 V3 V100R003C00"
},
{
"status": "affected",
"version": "RH2288 V3 V100R003C00"
},
{
"status": "affected",
"version": "RH2288H V3 V100R003C00"
},
{
"status": "affected",
"version": "XH310 V3 V100R003C00"
},
{
"status": "affected",
"version": "XH321 V3 V100R003C00"
},
{
"status": "affected",
"version": "XH321 V5 V100R005C00"
},
{
"status": "affected",
"version": "XH620 V3 V100R003C00"
}
]
}
]