Vulnerabilities > CVE-2017-17323 - Incorrect Authorization vulnerability in Huawei Ibmc Firmware V200R002C10/V200R002C20/V200R002C30

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
huawei
CWE-863

Summary

Huawei iBMC V200R002C10; V200R002C20; V200R002C30 have an improper authorization vulnerability. The software incorrectly performs an authorization check when a normal user attempts to access certain information which is supposed to be accessed only by admin user. Successful exploit could cause information disclosure.

Common Weakness Enumeration (CWE)