Description
FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-11861 | FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands. |
References
History
No history.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-09-16T23:50:49.849Z
Reserved: 2016-12-01T00:00:00.000Z
Link: CVE-2017-2718
No data.
Status : Modified
Published: 2017-11-22T19:29:01.287
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-2718
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD