Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20180131-01-IBMC
HistoryJan 31, 2018 - 12:00 a.m.

Security Advisory - Improper Authorization Vulnerability on iBMC

2018-01-3100:00:00
Huawei Technologies
www.huawei.com
28

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

21.7%

There is an improper authorization vulnerability on iBMC. The software incorrectly performs an authorization check when a normal user attempts to access certain information which is supposed to be accessed only by admin user. Successful exploit could cause information disclosure. (Vulnerability ID: HWPSIRT-2017-07182)

This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2017-17323.

Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:

http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180131-01-ibmc-en

Affected configurations

Vulners
Node
huaweich121_v3_firmwareMatchch121
OR
huaweich121_v3_firmwareMatchv3
OR
huaweich121_v3_firmwareMatchv100r001c00
OR
huaweich121l_v3_firmwareMatchch121l
OR
huaweich121l_v3_firmwareMatchv3
OR
huaweich121l_v3_firmwareMatchv100r001c00
OR
huaweich140_v3_firmwareMatchch140
OR
huaweich140_v3_firmwareMatchv3
OR
huaweich140_v3_firmwareMatchv100r001c00
OR
huaweich140l_v3_firmwareMatchch140l
OR
huaweich140l_v3_firmwareMatchv3
OR
huaweich140l_v3_firmwareMatchv100r001c00
OR
huaweich220_v3_firmwareMatchch220
OR
huaweich220_v3_firmwareMatchv3
OR
huaweich220_v3_firmwareMatchv100r001c00
OR
huaweich222_v3_firmwareMatchch222
OR
huaweich222_v3_firmwareMatchv3
OR
huaweich222_v3_firmwareMatchv100r001c00
OR
huaweich242_v3_firmwareMatchch242
OR
huaweich242_v3_firmwareMatchv3
OR
huaweich242_v3_firmwareMatchv100r001c00
OR
huaweirh1288_v3_firmwareMatchrh1288
OR
huaweirh1288_v3_firmwareMatchv3
OR
huaweirh1288_v3_firmwareMatchv100r003c00
OR
huaweirh2288_v3_firmwareMatchrh2288
OR
huaweirh2288_v3_firmwareMatchv3
OR
huaweirh2288_v3_firmwareMatchv100r003c00
OR
huaweirh2288h_v3_firmwareMatchrh2288h
OR
huaweirh2288h_v3_firmwareMatchv3
OR
huaweirh2288h_v3_firmwareMatchv100r003c00
OR
huaweixh310_v3_firmwareMatchxh310
OR
huaweixh310_v3_firmwareMatchv3
OR
huaweixh310_v3_firmwareMatchv100r003c00
OR
huaweixh321_v3_firmwareMatchxh321
OR
huaweixh321_v3_firmwareMatchv3
OR
huaweixh321_v3_firmwareMatchv100r003c00
OR
huaweixh620_v3_firmwareMatchxh620
OR
huaweixh620_v3_firmwareMatchv3
OR
huaweixh620_v3_firmwareMatchv100r003c00
OR
huaweich121_v5_firmwareMatchch121
OR
huaweich121_v5_firmwareMatchv5
OR
huaweich121_v5_firmwareMatchv100r001c00
OR
huaweich121l_v5_firmwareMatchch121l
OR
huaweich121l_v5_firmwareMatchv5
OR
huaweich121l_v5_firmwareMatchv100r001c00
OR
huaweich242_v5_firmwareMatchch242
OR
huaweich242_v5_firmwareMatchv5
OR
huaweich242_v5_firmwareMatchv100r001c00
OR
huawei1288h_v5_firmwareMatch1288h
OR
huawei1288h_v5_firmwareMatchv5
OR
huawei1288h_v5_firmwareMatchv100r005c00
OR
huawei2288h_v5_firmwareMatch2288h
OR
huawei2288h_v5_firmwareMatchv5
OR
huawei2288h_v5_firmwareMatchv100r005c00
OR
huawei2488_v5_firmwareMatch2488
OR
huawei2488_v5_firmwareMatchv5
OR
huawei2488_v5_firmwareMatchv100r005c00
OR
huaweixh321_v5_firmwareMatchxh321
OR
huaweixh321_v5_firmwareMatchv5
OR
huaweixh321_v5_firmwareMatchv100r005c00
VendorProductVersionCPE
huaweich121_v3_firmwarech121cpe:2.3:o:huawei:ch121_v3_firmware:ch121:*:*:*:*:*:*:*
huaweich121_v3_firmwarev3cpe:2.3:o:huawei:ch121_v3_firmware:v3:*:*:*:*:*:*:*
huaweich121_v3_firmwarev100r001c00cpe:2.3:o:huawei:ch121_v3_firmware:v100r001c00:*:*:*:*:*:*:*
huaweich121l_v3_firmwarech121lcpe:2.3:o:huawei:ch121l_v3_firmware:ch121l:*:*:*:*:*:*:*
huaweich121l_v3_firmwarev3cpe:2.3:o:huawei:ch121l_v3_firmware:v3:*:*:*:*:*:*:*
huaweich121l_v3_firmwarev100r001c00cpe:2.3:o:huawei:ch121l_v3_firmware:v100r001c00:*:*:*:*:*:*:*
huaweich140_v3_firmwarech140cpe:2.3:o:huawei:ch140_v3_firmware:ch140:*:*:*:*:*:*:*
huaweich140_v3_firmwarev3cpe:2.3:o:huawei:ch140_v3_firmware:v3:*:*:*:*:*:*:*
huaweich140_v3_firmwarev100r001c00cpe:2.3:o:huawei:ch140_v3_firmware:v100r001c00:*:*:*:*:*:*:*
huaweich140l_v3_firmwarech140lcpe:2.3:o:huawei:ch140l_v3_firmware:ch140l:*:*:*:*:*:*:*
Rows per page:
1-10 of 601

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

21.7%

Related for HUAWEI-SA-20180131-01-IBMC