CVE-2021-37106

HIGH

Huawei FusionCompute 6.3.0, 6.3.1, 6.5.0, 8.0.0 - Command Injection in CMA Service Module

Title source: llm
STIX 2.1

Description

There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system.

References (1)

Core 1

Scores

CVSS v3 7.2
EPSS 0.0053
EPSS Percentile 67.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (4)
huawei/fusioncompute 6.3.0
huawei/fusioncompute 6.3.1
huawei/fusioncompute 6.5.0
huawei/fusioncompute 8.0.0
Published Sep 28, 2021
Tracked Since Feb 18, 2026