Metrics
No CVSS v4.0
No CVSS v3.1
Attack Vector Network
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
Access Vector Network
Access Complexity Low
Authentication Single
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
This CVE is not in the KEV list.
The EPSS score is 0.00315.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Huawei
Subscribe
|
1288h V5
Subscribe
1288h V5 Firmware
Subscribe
2288h V5
Subscribe
2288h V5 Firmware
Subscribe
2488 V5
Subscribe
2488 V5 Firmware
Subscribe
Ch121 V3
Subscribe
Ch121 V3 Firmware
Subscribe
Ch121 V5
Subscribe
Ch121 V5 Firmware
Subscribe
Ch121l V3
Subscribe
Ch121l V3 Firmware
Subscribe
Ch121l V5
Subscribe
Ch121l V5 Firmware
Subscribe
Ch140 V3
Subscribe
Ch140 V3 Firmware
Subscribe
Ch140l V3
Subscribe
Ch140l V3 Firmware
Subscribe
Ch220 V3
Subscribe
Ch220 V3 Firmware
Subscribe
Ch222 V3
Subscribe
Ch222 V3 Firmware
Subscribe
Ch242 V3
Subscribe
Ch242 V3 Firmware
Subscribe
Ch242 V5
Subscribe
Ch242 V5 Firmware
Subscribe
Rh1288 V3
Subscribe
Rh1288 V3 Firmware
Subscribe
Rh2288 V3
Subscribe
Rh2288 V3 Firmware
Subscribe
Rh2288h V3
Subscribe
Rh2288h V3 Firmware
Subscribe
Xh310 V3
Subscribe
Xh310 V3 Firmware
Subscribe
Xh321 V3
Subscribe
Xh321 V3 Firmware
Subscribe
Xh321 V5
Subscribe
Xh321 V5 Firmware
Subscribe
Xh620 V3
Subscribe
Xh620 V3 Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-19662 | The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may allow attackers to obtain the management privilege of the system. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-08-05T06:37:59.581Z
Reserved: 2018-03-09T00:00:00
Link: CVE-2018-7950
No data.
Status : Modified
Published: 2018-06-01T14:29:00.830
Modified: 2024-11-21T04:13:00.710
Link: CVE-2018-7950
No data.
OpenCVE Enrichment
No data.
EUVD