cbcvebase.
CVE-2018-7941
published 2018-05-10

CVE-2018-7941: Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication…

high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due to improper validation of the upload authority, successful exploit may cause privilege elevation.

Affected

21 ranges
VendorProductVersion rangeFixed in
huawei1288h_v5_firmware
huawei2288h_v5_firmware
huawei2488_v5_firmware
huaweich121_v3_firmware
huaweich121_v5_firmware
huaweich121l_v3_firmware
huaweich121l_v5_firmware
huaweich140_v3_firmware
huaweich140l_v3_firmware
huaweich220_v3_firmware
huaweich222_v3_firmware
huaweich242_v3_firmware
huaweich242_v5_firmware
huaweirh1288_v3_firmware
huaweirh2288_v3_firmware
huaweirh2288h_v3_firmware
huaweixh310_v3_firmware
huaweixh321_v3_firmware
huaweixh321_v5_firmware
huaweixh620_v3_firmware
huawei_technologies_co_ltdibmc