Vulnerability CVE-2018-7951


Published: 2018-06-01

Description:
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may allow attackers to obtain the management privilege of the system.

Type:

CWE-74

CVSS2 => (AV:N/AC:L/Au:S/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9/10
10/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Huawei -> Rh2288h v3 firmware 
Huawei -> 1288h v5 firmware 
Huawei -> Xh310 v3 firmware 
Huawei -> 2288h v5 firmware 
Huawei -> Xh321 v3 firmware 
Huawei -> 2488 v5 firmware 
Huawei -> Xh321 v5 firmware 
Huawei -> Ch121 v3 firmware 
Huawei -> Xh620 v3 firmware 
Huawei -> Ch121 v5 firmware 
Huawei -> Ch121l v3 firmware 
Huawei -> Ch121l v5 firmware 
Huawei -> Ch140 v3 firmware 
Huawei -> Ch140l v3 firmware 
Huawei -> Ch220 v3 firmware 
Huawei -> Ch222 v3 firmware 
Huawei -> Ch242 v3 firmware 
Huawei -> Ch242 v5 firmware 
Huawei -> Rh1288 v3 firmware 
Huawei -> Rh2288 v3 firmware 

 References:
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180530-02-server-en

Copyright 2024, cxsecurity.com

 

Back to Top