The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-17097 | The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: huawei
Published:
Updated: 2024-09-16T22:45:01.432Z
Reserved: 2017-04-25T00:00:00
Link: CVE-2017-8135
No data.
Status : Deferred
Published: 2017-11-22T19:29:02.787
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-8135
No data.
OpenCVE Enrichment
No data.
EUVD