Description
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-17097 | The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands. |
References
History
No history.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-09-16T22:45:01.432Z
Reserved: 2017-04-25T00:00:00.000Z
Link: CVE-2017-8135
No data.
Status : Modified
Published: 2017-11-22T19:29:02.787
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-8135
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD