CVE-2018-7950
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
01/06/2018
Last modified:
24/08/2020
Description
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may allow attackers to obtain the management privilege of the system.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:1288h_v5_firmware:100r005c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:1288h_v5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:2288h_v5_firmware:100r005c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:2288h_v5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:2488_v5_firmware:100r005c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:2488_v5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ch121_v3_firmware:100r001c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:ch121_v3:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ch121l_v3_firmware:100r001c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:ch121l_v3:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ch121l_v5_firmware:100r001c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:ch121l_v5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ch121_v5_firmware:100r001c00:*:*:*:*:*:*:* | ||
| cpe:2.3:h:huawei:ch121_v5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:ch140_v3_firmware:100r001c00:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



