CVE-2017-8132

HIGH

FusionSphere OpenStack V100R006C00 and V100R006C10 - Unauthenticated Command Injection via TCP Listening Ports

Title source: llm
STIX 2.1

Description

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0030
EPSS Percentile 53.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (3)
huawei/fusionsphere_openstack v100r006c00
huawei/fusionsphere_openstack v100r006c10
Huawei Technologies Co., Ltd./FusionSphere OpenStack V100R006C00 and V100R006C10
Published Nov 22, 2017
Tracked Since Feb 18, 2026