Lucene search

K
huaweiHuawei TechnologiesHUAWEI-SA-20180530-03-SERVER
HistoryMay 30, 2018 - 12:00 a.m.

Security Advisory - Privilege Escalation Vulnerability in Some Huawei Servers

2018-05-3000:00:00
Huawei Technologies
www.huawei.com
11

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

66.4%

The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send some specially crafted login messages to the affected products. Due to improper authentication design, successful exploit enables low privileged users to get or modify passwords of highly privileged users. (Vulnerability ID: HWPSIRT-2018-02049)
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2018-7949.
Huawei has released software updates to fix this vulnerability. This advisory is available at the following link:
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180530-03-server-en

Affected configurations

Vulners
Node
huawei1288h_v5Matchv100r005c00
OR
huawei2288h_v5Matchv100r005c00
OR
huawei2488_v5Matchv100r005c00
OR
huaweifusionserver_ch121_v3Matchv100r001c00
OR
huaweich121lΒ v5Matchv100r001c00
OR
huaweich121l_v5Matchv100r001c00
OR
huaweifusionserver_ch121_v3Matchv100r001c00
OR
huaweich140Matchv100r001c00
OR
huaweifusionserver_ch220_v3Matchv100r001c00
OR
huaweifusionserver_ch220_v3Matchv100r001c00
OR
huaweifusionserver_ch222_v3Matchv100r001c00
OR
huawei●ch242Matchv100r001c00
OR
huaweich242_v5Matchv100r001c00
OR
huaweifusionserver_rh1288_v3Matchv100r003c00
OR
huaweifusionserver_rh2288_v3Matchv100r003c00
OR
huaweifusionserver_rh2288h_v3Matchv100r003c00
OR
huaweifusionserver_ch220_v3Matchv100r003c00
OR
huaweixh321_v5Matchv100r003c00
OR
huaweixh321_v5Matchv100r005c00
OR
huaweixh620Matchv100r003c00

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.003 Low

EPSS

Percentile

66.4%

Related for HUAWEI-SA-20180530-03-SERVER