Vulnerability Description
There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerability to get some sensitive information and high-level users' privilege.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | 1288H V5 Firmware | v100r005c00 |
| Huawei | 1288H V5 | - |
| Huawei | 2288H V5 Firmware | v100r005c00 |
| Huawei | 2288H V5 | - |
| Huawei | 2488 V5 Firmware | v100r005c00 |
| Huawei | 2488 V5 | - |
| Huawei | Ch121 V3 Firmware | v100r001c00 |
| Huawei | Ch121 V3 | - |
| Huawei | Ch121L V3 Firmware | v100r001c00 |
| Huawei | Ch121L V3 | - |
| Huawei | Ch121L V5 Firmware | v100r001c00 |
| Huawei | Ch121L V5 | - |
| Huawei | Ch121 V5 Firmware | v100r001c00 |
| Huawei | Ch121 V5 | - |
| Huawei | Ch140 V3 Firmware | v100r001c00 |
| Huawei | Ch140 V3 | - |
| Huawei | Ch140L V3 Firmware | v100r001c00 |
| Huawei | Ch140L V3 | - |
| Huawei | Ch220 V3 Firmware | v100r001c00 |
| Huawei | Ch220 V3 | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180530-01-server-Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180530-01-server-Vendor Advisory
FAQ
What is CVE-2018-7943?
CVE-2018-7943 is a vulnerability with a CVSS score of 8.8 (HIGH). There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authenticatio...
How severe is CVE-2018-7943?
CVE-2018-7943 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-7943?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei 1288H V5 Firmware, Huawei 1288H V5, Huawei 2288H V5 Firmware, Huawei 2288H V5, Huawei 2488 V5 Firmware.