Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due to improper validation of the upload authority, successful exploit may cause privilege elevation.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Huawei
Subscribe
|
1288h V5
Subscribe
1288h V5 Firmware
Subscribe
2288h V5
Subscribe
2288h V5 Firmware
Subscribe
2488 V5
Subscribe
2488 V5 Firmware
Subscribe
Ch121 V3
Subscribe
Ch121 V3 Firmware
Subscribe
Ch121 V5
Subscribe
Ch121 V5 Firmware
Subscribe
Ch121l V3
Subscribe
Ch121l V3 Firmware
Subscribe
Ch121l V5
Subscribe
Ch121l V5 Firmware
Subscribe
Ch140 V3
Subscribe
Ch140 V3 Firmware
Subscribe
Ch140l V3
Subscribe
Ch140l V3 Firmware
Subscribe
Ch220 V3
Subscribe
Ch220 V3 Firmware
Subscribe
Ch222 V3
Subscribe
Ch222 V3 Firmware
Subscribe
Ch242 V3
Subscribe
Ch242 V3 Firmware
Subscribe
Ch242 V5
Subscribe
Ch242 V5 Firmware
Subscribe
Rh1288 V3
Subscribe
Rh1288 V3 Firmware
Subscribe
Rh2288 V3
Subscribe
Rh2288 V3 Firmware
Subscribe
Rh2288h V3
Subscribe
Rh2288h V3 Firmware
Subscribe
Xh310 V3
Subscribe
Xh310 V3 Firmware
Subscribe
Xh321 V3
Subscribe
Xh321 V3 Firmware
Subscribe
Xh321 V5
Subscribe
Xh321 V5 Firmware
Subscribe
Xh620 V3
Subscribe
Xh620 V3 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-19653 | Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due to improper validation of the upload authority, successful exploit may cause privilege elevation. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-08-05T06:37:59.759Z
Reserved: 2018-03-09T00:00:00.000Z
Link: CVE-2018-7941
No data.
Status : Modified
Published: 2018-05-10T14:29:00.720
Modified: 2024-11-21T04:12:59.830
Link: CVE-2018-7941
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD