The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have an authentication bypass vulnerability. An unauthenticated, remote attacker may send some specially crafted messages to the affected products. Due to improper authentication design, successful exploit may cause some information leak.
References
Link | Resource |
---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180523-01-server-en | Broken Link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/143686 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
History
No history.
Information
Published : 2018-05-24 14:29
Updated : 2020-08-24 17:37
NVD link : CVE-2018-7942
Mitre link : CVE-2018-7942
CVE.ORG link : CVE-2018-7942
JSON object : View
Products Affected
huawei
- ch242_v3
- ch121l_v5
- 2488_v5
- 1288h_v5_firmware
- 1288h_v5
- 2488_v5_firmware
- 2288h_v5_firmware
- ch121_v3_firmware
- ch121l_v5_firmware
- 2288h_v5
- ch242_v3_firmware
- ch121l_v3_firmware
- ch121l_v3
- ch121_v3
CWE