Description
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send some specially crafted login messages to the affected products. Due to improper authentication design, successful exploit enables low privileged users to get or modify passwords of highly privileged users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-19661 | The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send some specially crafted login messages to the affected products. Due to improper authentication design, successful exploit enables low privileged users to get or modify passwords of highly privileged users. |
References
History
No history.
Subscriptions
Huawei
Subscribe
1288h V5
Subscribe
1288h V5 Firmware
Subscribe
2288h V5
Subscribe
2288h V5 Firmware
Subscribe
2488 V5
Subscribe
2488 V5 Firmware
Subscribe
Ch121 V3
Subscribe
Ch121 V3 Firmware
Subscribe
Ch121 V5
Subscribe
Ch121 V5 Firmware
Subscribe
Ch121l V3
Subscribe
Ch121l V3 Firmware
Subscribe
Ch121l V5
Subscribe
Ch121l V5 Firmware
Subscribe
Ch140 V3
Subscribe
Ch140 V3 Firmware
Subscribe
Ch140l V3
Subscribe
Ch140l V3 Firmware
Subscribe
Ch220 V3
Subscribe
Ch220 V3 Firmware
Subscribe
Ch222 V3
Subscribe
Ch222 V3 Firmware
Subscribe
Ch242 V3
Subscribe
Ch242 V3 Firmware
Subscribe
Ch242 V5
Subscribe
Ch242 V5 Firmware
Subscribe
Rh1288 V3
Subscribe
Rh1288 V3 Firmware
Subscribe
Rh2288 V3
Subscribe
Rh2288 V3 Firmware
Subscribe
Rh2288h V3
Subscribe
Rh2288h V3 Firmware
Subscribe
Xh310 V3
Subscribe
Xh310 V3 Firmware
Subscribe
Xh321 V3
Subscribe
Xh321 V3 Firmware
Subscribe
Xh321 V5
Subscribe
Xh321 V5 Firmware
Subscribe
Xh620 V3
Subscribe
Xh620 V3 Firmware
Subscribe
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-08-05T06:37:59.717Z
Reserved: 2018-03-09T00:00:00.000Z
Link: CVE-2018-7949
No data.
Status : Modified
Published: 2018-06-01T14:29:00.787
Modified: 2024-11-21T04:13:00.580
Link: CVE-2018-7949
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD