Improper Authorization in Huawei iBMC Affects User Access
CVE-2017-17323

4.3MEDIUM

Key Information:

Vendor
McAfee
Status
Vendor
CVE Published:
9 March 2018

Summary

Huawei iBMC software versions V200R002C10, V200R002C20, and V200R002C30 contain an improper authorization vulnerability. This issue arises when the software fails to perform adequate authorization checks, allowing non-privileged users to access sensitive information typically restricted to administrators. Exploitation of this vulnerability may lead to unintended information disclosure, posing potential risks to system security and data integrity.

Affected Version(s)

iBMC V200R002C10

iBMC V200R002C20

iBMC V200R002C30

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.