CVE-2017-8194

HIGH

FusionSphere OpenStack >=V100R006C00SPC102(NFV) - Authenticated Improper Authentication via REST Message

Title source: llm
STIX 2.1

Description

The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authenticated, remote attacker may exploit the vulnerability to execute more operations by send a crafted rest message.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102209

Scores

CVSS v3 8.8
EPSS 0.0037
EPSS Percentile 58.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (2)
huawei/fusionsphere_openstack v100r006c00spc102\(nfv\)
Huawei Technologies Co., Ltd./FusionSphere OpenStack V100R006C00SPC102(NFV)
Published Nov 22, 2017
Tracked Since Feb 18, 2026