Vulnerability Details CVE-2018-7941
Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due to improper validation of the upload authority, successful exploit may cause privilege elevation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.0%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2018-7941
-
cpe:2.3:h:huawei:1288h_v5:-
-
cpe:2.3:h:huawei:2288h_v5:-
-
cpe:2.3:h:huawei:2488_v5:-
-
cpe:2.3:h:huawei:ch121_v3:-
-
cpe:2.3:h:huawei:ch121_v5:-
-
cpe:2.3:h:huawei:ch121l_v3:-
-
cpe:2.3:h:huawei:ch121l_v5:-
-
cpe:2.3:h:huawei:ch140_v3:-
-
cpe:2.3:h:huawei:ch140l_v3:-
-
cpe:2.3:h:huawei:ch220_v3:-
-
cpe:2.3:h:huawei:ch222_v3:-
-
cpe:2.3:h:huawei:ch242_v3:-
-
cpe:2.3:h:huawei:ch242_v5:-
-
cpe:2.3:h:huawei:rh1288_v3:-
-
cpe:2.3:h:huawei:rh2288_v3:-
-
cpe:2.3:h:huawei:rh2288h_v3:-
-
cpe:2.3:h:huawei:xh310_v3:-
-
cpe:2.3:h:huawei:xh321_v3:-
-
cpe:2.3:h:huawei:xh321_v5:-
-
cpe:2.3:h:huawei:xh620_v3:-
-
cpe:2.3:o:huawei:1288h_v5_firmware:100r005c00
-
cpe:2.3:o:huawei:2288h_v5_firmware:100r005c00
-
cpe:2.3:o:huawei:2488_v5_firmware:100r005c00
-
cpe:2.3:o:huawei:ch121_v3_firmware:100r001c00
-
cpe:2.3:o:huawei:ch121_v5_firmware:100r001c00
-
cpe:2.3:o:huawei:ch121l_v3_firmware:100r001c00
-
cpe:2.3:o:huawei:ch121l_v5_firmware:100r001c00
-
cpe:2.3:o:huawei:ch140_v3_firmware:100r001c00
-
cpe:2.3:o:huawei:ch140l_v3_firmware:100r001c00
-
cpe:2.3:o:huawei:ch220_v3_firmware:100r001c00
-
cpe:2.3:o:huawei:ch222_v3_firmware:100r001c00
-
cpe:2.3:o:huawei:ch242_v3_firmware:100r001c00
-
cpe:2.3:o:huawei:ch242_v5_firmware:100r001c00
-
cpe:2.3:o:huawei:rh1288_v3_firmware:100r003c00
-
cpe:2.3:o:huawei:rh2288_v3_firmware:100r003c00
-
cpe:2.3:o:huawei:rh2288h_v3_firmware:100r003c00
-
cpe:2.3:o:huawei:xh310_v3_firmware:100r003c00
-
cpe:2.3:o:huawei:xh321_v3_firmware:100r003c00
-
cpe:2.3:o:huawei:xh321_v5_firmware:100r005c00
-
cpe:2.3:o:huawei:xh620_v3_firmware:100r003c00