Vulnerabilities > CVE-2022-28940 - Unspecified vulnerability in H3C Magic R100 Firmware V100R005

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
h3c

Summary

In H3C MagicR100 <=V100R005, the / Ajax / ajaxget interface can be accessed without authorization. It sends a large amount of data through ajaxmsg to carry out DOS attack.

Vulnerable Configurations

Part Description Count
OS
H3C
2
Hardware
H3C
1