CVE-2020-9116

HIGH

Huawei FusionCompute 6.5.1 and 8.0.0 - Authenticated Command Injection

Title source: llm
STIX 2.1

Description

Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to exploit this vulnerability. Due to insufficient verification, this could be exploited to cause the attackers to obtain higher privilege.

References (1)

Core 1

Scores

CVSS v3 7.2
EPSS 0.0147
EPSS Percentile 81.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (2)
huawei/fusioncompute 6.5.1
huawei/fusioncompute 8.0.0
Published Dec 01, 2020
Tracked Since Feb 18, 2026