ZeroHour

CVE-2018-7949

CVSS 3.0
8.8 high
EPSS
<1%p55
Published
()
Modified
Description

The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a privilege escalation vulnerability. A remote attacker may send some specially crafted login messages to the affected products. Due to improper authentication design, successful exploit enables low privileged users to get or modify passwords of highly privileged users.

Vendors
huawei
Products
1288h v5 firmware, 2288h v5 firmware, 2488 v5 firmware, ch121 v3 firmware, ch121l v3 firmware, ch121l v5 firmware, ch121 v5 firmware, ch140 v3 firmware, ch140l v3 firmware, ch220 v3 firmware, ch222 v3 firmware, ch242 v3 firmware
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.