CVE-2018-7943
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
05/06/2018
Last modified:
20/07/2018
Description
There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerability to get some sensitive information and high-level users' privilege.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:1288h_v5_firmware:v100r005c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:1288h_v5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:2288h_v5_firmware:v100r005c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:2288h_v5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:2488_v5_firmware:v100r005c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:2488_v5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ch121_v3_firmware:v100r001c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:ch121_v3:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ch121l_v3_firmware:v100r001c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:ch121l_v3:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ch121l_v5_firmware:v100r001c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:ch121l_v5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ch121_v5_firmware:v100r001c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:ch121_v5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ch140_v3_firmware:v100r001c00:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



