CVE-2015-7842
Summary
| CVE | CVE-2015-7842 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-10 01:30:00 UTC |
| Updated | 2017-11-05 23:14:00 UTC |
| Description | Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with software before V100R003C00SPC602, RH2288A V2 with software before V100R002C00SPC701, RH1288A V2 with software before V100R002C00SPC502, RH8100 V3 with software before V100R003C00SPC110, CH222 V3 with software before V100R001C00SPC161, CH220 V3 with software before V100R001C00SPC161, and CH121 V3 with software before V100R001C00SPC161 allow remote authenticated operators to change server information by leveraging failure to verify user permissions. |
Risk And Classification
Problem Types: CWE-275
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Ch121 V3 | - | All | All | All |
| Hardware | Huawei | Ch121 V3 | - | All | All | All |
| Operating System | Huawei | Ch121 V3 Firmware | All | All | All | All |
| Hardware | Huawei | Ch220 V3 | - | All | All | All |
| Hardware | Huawei | Ch220 V3 | - | All | All | All |
| Operating System | Huawei | Ch220 V3 Firmware | All | All | All | All |
| Hardware | Huawei | Ch222 V3 | - | All | All | All |
| Hardware | Huawei | Ch222 V3 | - | All | All | All |
| Operating System | Huawei | Ch222 V3 Firmware | All | All | All | All |
| Hardware | Huawei | Rh1288a V2 | - | All | All | All |
| Hardware | Huawei | Rh1288a V2 | - | All | All | All |
| Operating System | Huawei | Rh1288a V2 Firmware | All | All | All | All |
| Hardware | Huawei | Rh1288 V3 | - | All | All | All |
| Hardware | Huawei | Rh1288 V3 | - | All | All | All |
| Operating System | Huawei | Rh1288 V3 Firmware | All | All | All | All |
| Hardware | Huawei | Rh2288a V2 | - | All | All | All |
| Hardware | Huawei | Rh2288a V2 | - | All | All | All |
| Operating System | Huawei | Rh2288a V2 Firmware | All | All | All | All |
| Hardware | Huawei | Rh2288h V3 | - | All | All | All |
| Hardware | Huawei | Rh2288h V3 | - | All | All | All |
| Operating System | Huawei | Rh2288h V3 Firmware | All | All | All | All |
| Hardware | Huawei | Rh2288 V3 | - | All | All | All |
| Hardware | Huawei | Rh2288 V3 | - | All | All | All |
| Operating System | Huawei | Rh2288 V3 Firmware | All | All | All | All |
| Hardware | Huawei | Rh8100 V3 | - | All | All | All |
| Hardware | Huawei | Rh8100 V3 | - | All | All | All |
| Operating System | Huawei | Rh8100 V3 Firmware | All | All | All | All |
| Hardware | Huawei | Xh628 V3 | - | All | All | All |
| Hardware | Huawei | Xh628 V3 | - | All | All | All |
| Operating System | Huawei | Xh628 V3 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Huawei FusionServer products Security Bypass and Command Injection Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Security Advisory - Multiple Vulnerabilities in Huawei FusionServer Products | CONFIRM | www1.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.