CVE-2018-7950
—CVSS 3.0
8.8 high
EPSS
1%p72
Published
()
Modified
Description
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may allow attackers to obtain the management privilege of the system.
- Vendors
- huawei
- Products
- 1288h v5 firmware, 2288h v5 firmware, 2488 v5 firmware, ch121 v3 firmware, ch121l v3 firmware, ch121l v5 firmware, ch121 v5 firmware, ch140 v3 firmware, ch140l v3 firmware, ch220 v3 firmware, ch222 v3 firmware, ch242 v3 firmware
- Weakness
- CWE-94
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.