CVE-2018-7943

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
05/06/2018
Last modified:
20/07/2018

Description

There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerability to get some sensitive information and high-level users' privilege.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:1288h_v5_firmware:v100r005c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:1288h_v5:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:2288h_v5_firmware:v100r005c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:2288h_v5:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:2488_v5_firmware:v100r005c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:2488_v5:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ch121_v3_firmware:v100r001c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ch121_v3:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ch121l_v3_firmware:v100r001c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ch121l_v3:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ch121l_v5_firmware:v100r001c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ch121l_v5:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ch121_v5_firmware:v100r001c00:*:*:*:*:*:*:*
cpe:2.3:h:huawei:ch121_v5:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:ch140_v3_firmware:v100r001c00:*:*:*:*:*:*:*