8.8

CVE-2018-7943

There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerability to get some sensitive information and high-level users' privilege.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Huawei1288h V5 Firmware Versionv100r005c00
   Huawei1288h V5 Version-
Huawei2288h V5 Firmware Versionv100r005c00
   Huawei2288h V5 Version-
Huawei2488 V5 Firmware Versionv100r005c00
   Huawei2488 V5 Version-
HuaweiCh121 V3 Firmware Versionv100r001c00
   HuaweiCh121 V3 Version-
HuaweiCh121l V3 Firmware Versionv100r001c00
   HuaweiCh121l V3 Version-
HuaweiCh121l V5 Firmware Versionv100r001c00
   HuaweiCh121l V5 Version-
HuaweiCh121 V5 Firmware Versionv100r001c00
   HuaweiCh121 V5 Version-
HuaweiCh140 V3 Firmware Versionv100r001c00
   HuaweiCh140 V3 Version-
HuaweiCh140l V3 Firmware Versionv100r001c00
   HuaweiCh140l V3 Version-
HuaweiCh220 V3 Firmware Versionv100r001c00
   HuaweiCh220 V3 Version-
HuaweiCh222 V3 Firmware Versionv100r001c00
   HuaweiCh222 V3 Version-
HuaweiCh242 V3 Firmware Versionv100r001c00
   HuaweiCh242 V3 Version-
HuaweiCh242 V5 Firmware Versionv100r001c00
   HuaweiCh242 V5 Version-
HuaweiRh1288 V3 Firmware Versionv100r003c00
   HuaweiRh1288 V3 Version-
HuaweiRh2288 V3 Firmware Versionv100r003c00
   HuaweiRh2288 V3 Version-
HuaweiRh2288h V3 Firmware Versionv100r003c00
   HuaweiRh2288h V3 Version-
HuaweiXh310 V3 Firmware Versionv100r003c00
   HuaweiXh310 V3 Version-
HuaweiXh321 V3 Firmware Versionv100r003c00
   HuaweiXh321 V3 Version-
HuaweiXh321 V5 Firmware Versionv100r005c00
   HuaweiXh321 V5 Version-
HuaweiXh620 V3 Firmware Versionv100r003c00
   HuaweiXh620 V3 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.481
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.