First published: Wed May 30 2018(Updated: )
There is an authentication bypass vulnerability in some Huawei servers. A remote attacker with low privilege may bypass the authentication by some special operations. Due to insufficient authentication, an attacker may exploit the vulnerability to get some sensitive information and high-level users' privilege.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei 1288h V5 Firmware | =v100r005c00 | |
Huawei 1288H V5 | ||
Huawei 2288h V5 Firmware | =v100r005c00 | |
Huawei 2288h V5 | ||
Huawei 2488 V5 Firmware | =v100r005c00 | |
Huawei 2488 V5 | ||
Huawei Ch121 V3 Firmware | =v100r001c00 | |
Huawei Ch121 V3 | ||
Huawei Ch121l V3 Firmware | =v100r001c00 | |
Huawei Ch121l V3 | ||
Huawei Ch121l V5 Firmware | =v100r001c00 | |
Huawei Ch121l V5 | ||
Huawei Ch121 V5 Firmware | =v100r001c00 | |
Huawei Ch121 V5 | ||
Huawei Ch140 V3 Firmware | =v100r001c00 | |
Huawei Ch140 V3 | ||
Huawei Ch140l V3 Firmware | =v100r001c00 | |
Huawei Ch140l V3 | ||
Huawei Ch220 V3 Firmware | =v100r001c00 | |
Huawei Ch220 V3 | ||
Huawei Ch222 V3 Firmware | =v100r001c00 | |
Huawei Ch222 V3 | ||
Huawei Ch242 V3 Firmware | =v100r001c00 | |
Huawei Ch242 V3 | ||
Huawei Ch242 V5 Firmware | =v100r001c00 | |
Huawei Ch242 V5 | ||
Huawei Rh1288 V3 Firmware | =v100r003c00 | |
Huawei Rh1288 V3 | ||
Huawei Rh2288 V3 Firmware | =v100r003c00 | |
Huawei Rh2288 V3 | ||
Huawei Rh2288h V3 Firmware | =v100r003c00 | |
Huawei Rh2288h V3 | ||
Huawei Xh310 V3 Firmware | =v100r003c00 | |
Huawei Xh310 V3 | ||
Huawei Xh321 V3 Firmware | =v100r003c00 | |
Huawei Xh321 V3 | ||
Huawei Xh321 V5 Firmware | =v100r005c00 | |
Huawei Xh321 V5 | ||
Huawei Xh620 V3 Firmware | =v100r003c00 | |
Huawei Xh620 V3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.