Vulnerability Description
Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due to improper validation of the upload authority, successful exploit may cause privilege elevation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Ch121 V3 Firmware | 100r001c00 |
| Huawei | Ch121 V3 | - |
| Huawei | Ch121L V3 Firmware | 100r001c00 |
| Huawei | Ch121L V3 | - |
| Huawei | Ch140 V3 Firmware | 100r001c00 |
| Huawei | Ch140 V3 | - |
| Huawei | Ch140L V3 Firmware | 100r001c00 |
| Huawei | Ch140L V3 | - |
| Huawei | Ch220 V3 Firmware | 100r001c00 |
| Huawei | Ch220 V3 | - |
| Huawei | Ch222 V3 Firmware | 100r001c00 |
| Huawei | Ch222 V3 | - |
| Huawei | Ch242 V3 Firmware | 100r001c00 |
| Huawei | Ch242 V3 | - |
| Huawei | Rh1288 V3 Firmware | 100r003c00 |
| Huawei | Rh1288 V3 | - |
| Huawei | Rh2288 V3 Firmware | 100r003c00 |
| Huawei | Rh2288 V3 | - |
| Huawei | Rh2288H V3 Firmware | 100r003c00 |
| Huawei | Rh2288H V3 | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180509-01-bypass-Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180509-01-bypass-Vendor Advisory
FAQ
What is CVE-2018-7941?
CVE-2018-7941 is a vulnerability with a CVSS score of 8.8 (HIGH). Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due...
How severe is CVE-2018-7941?
CVE-2018-7941 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-7941?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Ch121 V3 Firmware, Huawei Ch121 V3, Huawei Ch121L V3 Firmware, Huawei Ch121L V3, Huawei Ch140 V3 Firmware.