The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may allow attackers to obtain the management privilege of the system.
2018-06-01T14:29:00.877
2024-11-21T04:13:00.843
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | huawei | 1288h_v5_firmware | 100r005c00 | Yes |
Hardware | huawei | 1288h_v5 | - | No |
Operating System | huawei | 2288h_v5_firmware | 100r005c00 | Yes |
Hardware | huawei | 2288h_v5 | - | No |
Operating System | huawei | 2488_v5_firmware | 100r005c00 | Yes |
Hardware | huawei | 2488_v5 | - | No |
Operating System | huawei | ch121_v3_firmware | 100r001c00 | Yes |
Hardware | huawei | ch121_v3 | - | No |
Operating System | huawei | ch121l_v3_firmware | 100r001c00 | Yes |
Hardware | huawei | ch121l_v3 | - | No |
Operating System | huawei | ch121l_v5_firmware | 100r001c00 | Yes |
Hardware | huawei | ch121l_v5 | - | No |
Operating System | huawei | ch121_v5_firmware | 100r001c00 | Yes |
Hardware | huawei | ch121_v5 | - | No |
Operating System | huawei | ch140_v3_firmware | 100r001c00 | Yes |
Hardware | huawei | ch140_v3 | - | No |
Operating System | huawei | ch140l_v3_firmware | 100r001c00 | Yes |
Hardware | huawei | ch140l_v3 | - | No |
Operating System | huawei | ch220_v3_firmware | 100r001c00 | Yes |
Hardware | huawei | ch220_v3 | - | No |
Operating System | huawei | ch222_v3_firmware | 100r001c00 | Yes |
Hardware | huawei | ch222_v3 | - | No |
Operating System | huawei | ch242_v3_firmware | 100r001c00 | Yes |
Hardware | huawei | ch242_v3 | - | No |
Operating System | huawei | ch242_v5_firmware | 100r001c00 | Yes |
Hardware | huawei | ch242_v5 | - | No |
Operating System | huawei | rh1288_v3_firmware | 100r003c00 | Yes |
Hardware | huawei | rh1288_v3 | - | No |
Operating System | huawei | rh2288_v3_firmware | 100r003c00 | Yes |
Hardware | huawei | rh2288_v3 | - | No |
Operating System | huawei | xh310_v3_firmware | 100r003c00 | Yes |
Hardware | huawei | xh310_v3 | - | No |
Operating System | huawei | xh321_v3_firmware | 100r003c00 | Yes |
Hardware | huawei | xh321_v3 | - | No |
Operating System | huawei | xh321_v5_firmware | 100r005c00 | Yes |
Hardware | huawei | xh321_v5 | - | No |
Operating System | huawei | rh2288h_v3_firmware | 100r003c00 | Yes |
Hardware | huawei | rh2288h_v3 | - | No |
Operating System | huawei | xh620_v3_firmware | 100r003c00 | Yes |
Hardware | huawei | xh620_v3 | - | No |