Vulnerability CVE-2018-7949


Published: 2018-06-01

Description:
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send some specially crafted login messages to the affected products. Due to improper authentication design, successful exploit enables low privileged users to get or modify passwords of highly privileged users.

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Huawei -> Rh2288h v3 firmware 
Huawei -> 1288h v5 firmware 
Huawei -> Xh310 v3 firmware 
Huawei -> 2288h v5 firmware 
Huawei -> Xh321 v3 firmware 
Huawei -> 2488 v5 firmware 
Huawei -> Xh321 v5 firmware 
Huawei -> Ch121 v3 firmware 
Huawei -> Xh620 v3 firmware 
Huawei -> Ch121 v5 firmware 
Huawei -> Ch121l v3 firmware 
Huawei -> Ch121l v5 firmware 
Huawei -> Ch140 v3 firmware 
Huawei -> Ch140l v3 firmware 
Huawei -> Ch220 v3 firmware 
Huawei -> Ch222 v3 firmware 
Huawei -> Ch242 v3 firmware 
Huawei -> Ch242 v5 firmware 
Huawei -> Rh1288 v3 firmware 
Huawei -> Rh2288 v3 firmware 

 References:
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180530-03-server-en

Copyright 2024, cxsecurity.com

 

Back to Top