CVE-2021-37102

HIGH

FusionCompute 6.0.0, 6.3.0, 6.3.1, 6.5.0, 6.5.1, 8.0.0 - Command Injection in CMA Service Module

Title source: llm
STIX 2.1

Description

There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system. Affected product versions include: FusionCompute 6.0.0, 6.3.0, 6.3.1, 6.5.0, 6.5.1, 8.0.0.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0064
EPSS Percentile 70.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (6)
huawei/fusioncompute 6.0.0
huawei/fusioncompute 6.3.0
huawei/fusioncompute 6.3.1
huawei/fusioncompute 6.5.0
huawei/fusioncompute 6.5.1
huawei/fusioncompute 8.0.0
Published Nov 23, 2021
Tracked Since Feb 18, 2026