ID

VAR-201805-1003


CVE

CVE-2018-7904


TITLE

Huawei 1288H V5 and 2288H V5 Software injection command vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-005295

DESCRIPTION

Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Due to insufficient verification of the input, this could be exploited to obtain the management privilege of the system. Huawei 1288H V5 and 2288H V5 The software contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Huawei1288HV5 and 2288HV5 are rack routers, which can be widely used in cloud computing virtualization, database, big data and other workloads. The vulnerability stems from a program that fails to adequately verify input

Trust: 2.25

sources: NVD: CVE-2018-7904 // JVNDB: JVNDB-2018-005295 // CNVD: CNVD-2018-15389 // VULHUB: VHN-137936

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-15389

AFFECTED PRODUCTS

vendor:huaweimodel:1288h v5scope:eqversion:v100r005c00

Trust: 2.4

vendor:huaweimodel:2288h v5scope:eqversion:v100r005c00

Trust: 2.4

vendor:huaweimodel:1288h v100r005c00scope:eqversion:v5

Trust: 0.6

vendor:huaweimodel:2288h v100r005c00scope:eqversion:v5

Trust: 0.6

sources: CNVD: CNVD-2018-15389 // JVNDB: JVNDB-2018-005295 // CNNVD: CNNVD-201805-821 // NVD: CVE-2018-7904

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-7904
value: HIGH

Trust: 1.0

NVD: CVE-2018-7904
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-15389
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201805-821
value: HIGH

Trust: 0.6

VULHUB: VHN-137936
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-7904
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-15389
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-137936
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-7904
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-15389 // VULHUB: VHN-137936 // JVNDB: JVNDB-2018-005295 // CNNVD: CNNVD-201805-821 // NVD: CVE-2018-7904

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-77

Trust: 0.9

sources: VULHUB: VHN-137936 // JVNDB: JVNDB-2018-005295 // NVD: CVE-2018-7904

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201805-821

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201805-821

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-005295

PATCH

title:huawei-sa-20180523-01-jsonurl:https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180523-01-json-en

Trust: 0.8

title:Huawei 1288H and 2288H Rack Server JSON Injection Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/137447

Trust: 0.6

title:Huawei 1288H V5 and 2288H V5 Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=83696

Trust: 0.6

sources: CNVD: CNVD-2018-15389 // JVNDB: JVNDB-2018-005295 // CNNVD: CNNVD-201805-821

EXTERNAL IDS

db:NVDid:CVE-2018-7904

Trust: 3.1

db:JVNDBid:JVNDB-2018-005295

Trust: 0.8

db:CNVDid:CNVD-2018-15389

Trust: 0.6

db:CNNVDid:CNNVD-201805-821

Trust: 0.6

db:VULHUBid:VHN-137936

Trust: 0.1

sources: CNVD: CNVD-2018-15389 // VULHUB: VHN-137936 // JVNDB: JVNDB-2018-005295 // CNNVD: CNNVD-201805-821 // NVD: CVE-2018-7904

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180523-01-json-en

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-7904

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-7904

Trust: 0.8

sources: CNVD: CNVD-2018-15389 // VULHUB: VHN-137936 // JVNDB: JVNDB-2018-005295 // CNNVD: CNNVD-201805-821 // NVD: CVE-2018-7904

SOURCES

db:CNVDid:CNVD-2018-15389
db:VULHUBid:VHN-137936
db:JVNDBid:JVNDB-2018-005295
db:CNNVDid:CNNVD-201805-821
db:NVDid:CVE-2018-7904

LAST UPDATE DATE

2024-11-23T22:52:05.090000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-15389date:2018-08-16T00:00:00
db:VULHUBid:VHN-137936date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-005295date:2018-07-11T00:00:00
db:CNNVDid:CNNVD-201805-821date:2019-10-23T00:00:00
db:NVDid:CVE-2018-7904date:2024-11-21T04:12:56.947

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-15389date:2018-08-15T00:00:00
db:VULHUBid:VHN-137936date:2018-05-24T00:00:00
db:JVNDBid:JVNDB-2018-005295date:2018-07-11T00:00:00
db:CNNVDid:CNNVD-201805-821date:2018-05-25T00:00:00
db:NVDid:CVE-2018-7904date:2018-05-24T14:29:00.530