CVE-2018-7943
published 2018-06-05CVE-2018-7943: There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special…
PriorityP351high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.23%
65.7th percentile
There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerability to get some sensitive information and high-level users' privilege.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| huawei | 1288h_v5_firmware | — | — |
| huawei | 2288h_v5_firmware | — | — |
| huawei | 2488_v5_firmware | — | — |
| huawei | ch121_v3_firmware | — | — |
| huawei | ch121_v5_firmware | — | — |
| huawei | ch121l_v3_firmware | — | — |
| huawei | ch121l_v5_firmware | — | — |
| huawei | ch140_v3_firmware | — | — |
| huawei | ch140l_v3_firmware | — | — |
| huawei | ch220_v3_firmware | — | — |
| huawei | ch222_v3_firmware | — | — |
| huawei | ch242_v3_firmware | — | — |
| huawei | ch242_v5_firmware | — | — |
| huawei | rh1288_v3_firmware | — | — |
| huawei | rh2288_v3_firmware | — | — |
| huawei | rh2288h_v3_firmware | — | — |
| huawei | xh310_v3_firmware | — | — |
| huawei | xh321_v3_firmware | — | — |
| huawei | xh321_v5_firmware | — | — |
| huawei | xh620_v3_firmware | — | — |
| x.org | libx11 | >= 0 < 2:1.6.2-1ubuntu2.1 | 2:1.6.2-1ubuntu2.1 |
| x.org | libx11 | >= 0 < 2:1.6.3-1ubuntu2.1 | 2:1.6.3-1ubuntu2.1 |
| x.org | libx11 | >= 0 < 2:1.6.4-3ubuntu0.1 | 2:1.6.4-3ubuntu0.1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv9.8CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qp67-v7w7-r9vj: There is an authentication bypass vulnerability in some Huawei servers
ghsa_unreviewed·2022-05-14
CVE-2018-7943 [HIGH] CWE-287 GHSA-qp67-v7w7-r9vj: There is an authentication bypass vulnerability in some Huawei servers
There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerability to get some sensitive information and high-level users' privilege.
OSV
libx11 vulnerabilities
osv·2018-08-30·CVSS 9.8
CVE-2016-7942 libx11 vulnerabilities
libx11 vulnerabilities
Tobias Stoeckmann discovered that libx11 incorrectly handled certain images.
An attacker could possibly use this issue to access sensitive information
(CVE-2016-7942)
Tobias Stoeckmann discovered that libx11 incorrectly handled certain inputs.
An attacker could possibly use this issue to access sensitive information.
(CVE-2016-7943)
It was discovered that libx11 incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-14598, CVE-2018-14599, CVE-2018-14600)
Red Hat
puppet: puppet server and puppetDB may leak sensitive information via metrics API
vendor_redhat·2020-03-10·CVSS 7.5
CVE-2020-7943 [HIGH] CWE-276 puppet: puppet server and puppetDB may leak sensitive information via metrics API
puppet: puppet server and puppetDB may leak sensitive information via metrics API
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.5.0, Puppet Server 6.9.2 & 5.3.12, and PuppetDB 6.9.1 & 5.2.13 disable trapperkeeper-metrics /v1 metrics API and only allows /v2 access on localhost by default. This affects software versions: Puppet Enterprise 2018.1.x stream prior to 2018.1.13 Puppet Enterprise prior to 2019.5.0 Puppet Server prior to 6.9.2 Puppet Se
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-06-05
Published