The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation
Published Jun 1, 2018
8.8
HIGHCVSS 3.0
EPSS 1.46%
Description
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Successful exploit may allow attackers to obtain the management privilege of the system.
Affected products
-
Affected
- 1288H V5 V100R005C00
- 2288H V5 V100R005C00
- 2488 V5 V100R005C00
- CH121 V3 V100R001C00
- CH121 V5 V100R001C00
- CH121L V3 V100R001C00
- CH121L V5 V100R001C00
- CH140 V3 V100R001C00
- CH140L V3 V100R001C00
- CH220 V3 V100R001C00
- CH222 V3 V100R001C00
- CH242 V3 V100R001C00
- CH242 V5 V100R001C00
- RH1288 V3 V100R003C00
- RH2288 V3 V100R003C00
- RH2288H V3 V100R003C00
- XH310 V3 V100R003C00
- XH321 V3 V100R003C00
- XH321 V5 V100R005C00
- XH620 V3 V100R003C00
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Huawei Technologies Co., Ltd. | n/a | unknown | Affected
|
Configuration 1
- 100r005c00
Configuration 2
- 100r005c00
Configuration 3
- 100r005c00
Configuration 4
- 100r001c00
Configuration 5
- 100r001c00
Configuration 6
- 100r001c00
Configuration 7
- 100r001c00
Configuration 8
- 100r001c00
Configuration 9
- 100r001c00
Configuration 10
- 100r001c00
Configuration 11
- 100r001c00
Configuration 12
- 100r001c00
Configuration 13
- 100r001c00
Configuration 14
- 100r003c00
Configuration 15
- 100r003c00
Configuration 16
- 100r003c00
Configuration 17
- 100r003c00
Configuration 18
- 100r005c00
Configuration 19
- 100r003c00
Running on/with
- n/a
Configuration 20
- 100r003c00
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180530-02-server-en x_refsource_CONFIRMVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-19663 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180530-02-server-en | x_refsource_CONFIRMVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-19663 | Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data