ID

VAR-201809-1116


CVE

CVE-2018-7937


TITLE

Huawei HiRouter-CD20-10 and WS5200-10 Vulnerabilities related to authorization, permissions, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2018-009495

DESCRIPTION

In Huawei HiRouter-CD20-10 with the versions before 1.9.6 and WS5200-10 with the versions before 1.9.6, there is a plug-in signature bypass vulnerability due to insufficient plug-in verification. An attacker may tamper with a legitimate plug-in to build a malicious plug-in and trick users into installing it. Successful exploit could allow the attacker to obtain the root permission of the device and take full control over the device. Huawei HiRouter-CD20-10 and WS5200-10 Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Huawei HiRouter-CD20 and WS5200-10 are both home router products released by Huawei

Trust: 2.16

sources: NVD: CVE-2018-7937 // JVNDB: JVNDB-2018-009495 // CNVD: CNVD-2018-16536

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-16536

AFFECTED PRODUCTS

vendor:huaweimodel:ws5200-10scope:ltversion:1.9.6

Trust: 1.4

vendor:huaweimodel:ws5200-10scope:ltversion:ws5200-10_1.9.6

Trust: 1.0

vendor:huaweimodel:hirouter-cd20scope:ltversion:hirouter-cd20-10_1.9.6

Trust: 1.0

vendor:huaweimodel:hirouter-cd20scope:ltversion:1.9.6

Trust: 0.8

vendor:huaweimodel:hirouter-cd20 <hirouter-cd20-10scope:eqversion:1.9.6

Trust: 0.6

sources: CNVD: CNVD-2018-16536 // JVNDB: JVNDB-2018-009495 // NVD: CVE-2018-7937

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-7937
value: HIGH

Trust: 1.0

NVD: CVE-2018-7937
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-16536
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201808-861
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2018-7937
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-16536
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2018-7937
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-16536 // JVNDB: JVNDB-2018-009495 // CNNVD: CNNVD-201808-861 // NVD: CVE-2018-7937

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-264

Trust: 0.8

sources: JVNDB: JVNDB-2018-009495 // NVD: CVE-2018-7937

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201808-861

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201808-861

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-009495

PATCH

title:huawei-sa-20180827-01-gatewayurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180827-01-gateway-en

Trust: 0.8

title:A variety of Huawei product plug-in signatures bypass the vulnerability patchurl:https://www.cnvd.org.cn/patchInfo/show/138573

Trust: 0.6

title:Huawei HiRouter-CD20 and WS5200 Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=84314

Trust: 0.6

sources: CNVD: CNVD-2018-16536 // JVNDB: JVNDB-2018-009495 // CNNVD: CNNVD-201808-861

EXTERNAL IDS

db:NVDid:CVE-2018-7937

Trust: 3.0

db:JVNDBid:JVNDB-2018-009495

Trust: 0.8

db:CNVDid:CNVD-2018-16536

Trust: 0.6

db:CNNVDid:CNNVD-201808-861

Trust: 0.6

sources: CNVD: CNVD-2018-16536 // JVNDB: JVNDB-2018-009495 // CNNVD: CNNVD-201808-861 // NVD: CVE-2018-7937

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180827-01-gateway-en

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-7937

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-7937

Trust: 0.8

url:https://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20180827-01-gateway-cn

Trust: 0.6

sources: CNVD: CNVD-2018-16536 // JVNDB: JVNDB-2018-009495 // CNNVD: CNNVD-201808-861 // NVD: CVE-2018-7937

SOURCES

db:CNVDid:CNVD-2018-16536
db:JVNDBid:JVNDB-2018-009495
db:CNNVDid:CNNVD-201808-861
db:NVDid:CVE-2018-7937

LAST UPDATE DATE

2024-11-23T21:38:16.891000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-16536date:2018-08-28T00:00:00
db:JVNDBid:JVNDB-2018-009495date:2018-11-20T00:00:00
db:CNNVDid:CNNVD-201808-861date:2019-10-23T00:00:00
db:NVDid:CVE-2018-7937date:2024-11-21T04:12:59.360

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-16536date:2018-08-28T00:00:00
db:JVNDBid:JVNDB-2018-009495date:2018-11-20T00:00:00
db:CNNVDid:CNNVD-201808-861date:2018-08-28T00:00:00
db:NVDid:CVE-2018-7937date:2018-09-04T16:29:00.753