ID

VAR-202205-0312


CVE

CVE-2022-28940


TITLE

H3C  of  magic r100  Fraudulent Authentication Vulnerability in Firmware

Trust: 0.8

sources: JVNDB: JVNDB-2022-009224

DESCRIPTION

In H3C MagicR100 <=V100R005, the / Ajax / ajaxget interface can be accessed without authorization. It sends a large amount of data through ajaxmsg to carry out DOS attack. H3C of magic r100 An incorrect authentication vulnerability exists in firmware.Service operation interruption (DoS) It may be in a state. H3C MagicR100 is a router from H3C company. There is a security vulnerability in H3C MagicR100

Trust: 2.25

sources: NVD: CVE-2022-28940 // JVNDB: JVNDB-2022-009224 // CNVD: CNVD-2022-50718 // VULMON: CVE-2022-28940

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2022-50718

AFFECTED PRODUCTS

vendor:h3cmodel:magic r100scope:lteversion:v100r005

Trust: 1.0

vendor:h3cmodel:magic r100scope: - version: -

Trust: 0.8

vendor:h3cmodel:magic r100scope:eqversion: -

Trust: 0.8

vendor:h3cmodel:magic r100scope:lteversion:magic r100 firmware v100r005 and earlier

Trust: 0.8

vendor:h3cmodel:magicr100 <=v100r005scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2022-50718 // JVNDB: JVNDB-2022-009224 // NVD: CVE-2022-28940

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-28940
value: HIGH

Trust: 1.0

NVD: CVE-2022-28940
value: HIGH

Trust: 0.8

CNVD: CNVD-2022-50718
value: HIGH

Trust: 0.6

CNNVD: CNNVD-202205-2138
value: HIGH

Trust: 0.6

VULMON: CVE-2022-28940
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2022-28940
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2022-50718
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2022-28940
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2022-28940
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2022-50718 // VULMON: CVE-2022-28940 // JVNDB: JVNDB-2022-009224 // CNNVD: CNNVD-202205-2138 // NVD: CVE-2022-28940

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Illegal authentication (CWE-863) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2022-009224 // NVD: CVE-2022-28940

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202205-2138

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202205-2138

PATCH

title:Patch for H3C MagicR100 has an unknown vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/338951

Trust: 0.6

title:H3C MagicR100 Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=193074

Trust: 0.6

sources: CNVD: CNVD-2022-50718 // CNNVD: CNNVD-202205-2138

EXTERNAL IDS

db:NVDid:CVE-2022-28940

Trust: 3.9

db:JVNDBid:JVNDB-2022-009224

Trust: 0.8

db:CNVDid:CNVD-2022-50718

Trust: 0.6

db:CNNVDid:CNNVD-202205-2138

Trust: 0.6

db:VULMONid:CVE-2022-28940

Trust: 0.1

sources: CNVD: CNVD-2022-50718 // VULMON: CVE-2022-28940 // JVNDB: JVNDB-2022-009224 // CNNVD: CNNVD-202205-2138 // NVD: CVE-2022-28940

REFERENCES

url:https://github.com/zhefox/0day/blob/main/%e6%96%b0%e5%8d%8e%e4%b8%89magicr100%e5%ad%98%e5%9c%a8dos%e6%94%bb%e5%87%bb%e6%bc%8f%e6%b4%9e%e5%88%86%e6%9e%90.md

Trust: 2.5

url:https://cxsecurity.com/cveshow/cve-2022-28940/

Trust: 1.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-28940

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/863.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2022-50718 // VULMON: CVE-2022-28940 // JVNDB: JVNDB-2022-009224 // CNNVD: CNNVD-202205-2138 // NVD: CVE-2022-28940

SOURCES

db:CNVDid:CNVD-2022-50718
db:VULMONid:CVE-2022-28940
db:JVNDBid:JVNDB-2022-009224
db:CNNVDid:CNNVD-202205-2138
db:NVDid:CVE-2022-28940

LAST UPDATE DATE

2024-11-23T23:07:25.213000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2022-50718date:2022-07-11T00:00:00
db:VULMONid:CVE-2022-28940date:2022-05-16T00:00:00
db:JVNDBid:JVNDB-2022-009224date:2023-08-03T08:29:00
db:CNNVDid:CNNVD-202205-2138date:2022-05-17T00:00:00
db:NVDid:CVE-2022-28940date:2024-11-21T06:58:13.410

SOURCES RELEASE DATE

db:CNVDid:CNVD-2022-50718date:2022-07-11T00:00:00
db:VULMONid:CVE-2022-28940date:2022-05-04T00:00:00
db:JVNDBid:JVNDB-2022-009224date:2023-08-03T00:00:00
db:CNNVDid:CNNVD-202205-2138date:2022-05-04T00:00:00
db:NVDid:CVE-2022-28940date:2022-05-04T16:15:08.743