The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may allow attackers to obtain the management privilege of the system.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Huawei
Subscribe
|
1288h V5
Subscribe
1288h V5 Firmware
Subscribe
2288h V5
Subscribe
2288h V5 Firmware
Subscribe
2488 V5
Subscribe
2488 V5 Firmware
Subscribe
Ch121 V3
Subscribe
Ch121 V3 Firmware
Subscribe
Ch121 V5
Subscribe
Ch121 V5 Firmware
Subscribe
Ch121l V3
Subscribe
Ch121l V3 Firmware
Subscribe
Ch121l V5
Subscribe
Ch121l V5 Firmware
Subscribe
Ch140 V3
Subscribe
Ch140 V3 Firmware
Subscribe
Ch140l V3
Subscribe
Ch140l V3 Firmware
Subscribe
Ch220 V3
Subscribe
Ch220 V3 Firmware
Subscribe
Ch222 V3
Subscribe
Ch222 V3 Firmware
Subscribe
Ch242 V3
Subscribe
Ch242 V3 Firmware
Subscribe
Ch242 V5
Subscribe
Ch242 V5 Firmware
Subscribe
Rh1288 V3
Subscribe
Rh1288 V3 Firmware
Subscribe
Rh2288 V3
Subscribe
Rh2288 V3 Firmware
Subscribe
Rh2288h V3
Subscribe
Rh2288h V3 Firmware
Subscribe
Xh310 V3
Subscribe
Xh310 V3 Firmware
Subscribe
Xh321 V3
Subscribe
Xh321 V3 Firmware
Subscribe
Xh321 V5
Subscribe
Xh321 V5 Firmware
Subscribe
Xh620 V3
Subscribe
Xh620 V3 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-19663 | The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may allow attackers to obtain the management privilege of the system. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-08-05T06:37:59.585Z
Reserved: 2018-03-09T00:00:00.000Z
Link: CVE-2018-7951
No data.
Status : Modified
Published: 2018-06-01T14:29:00.877
Modified: 2024-11-21T04:13:00.843
Link: CVE-2018-7951
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD