First published: Wed Nov 22 2017(Updated: )
FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei FusionSphere OpenStack | =v100r006c00 | |
Huawei FusionSphere OpenStack | =v100r006c10-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2718 is a vulnerability in FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 that allows for command injection exploits.
The severity of CVE-2017-2718 is high, with a severity value of 8.8.
An attacker can gain root privileges by exploiting CVE-2017-2718 through sending messages with malicious commands.
FusionSphere OpenStack versions V100R006C00 and V100R006C10RC2 are affected by CVE-2017-2718.
Yes, Huawei has released a security advisory with fixes for CVE-2017-2718. Please refer to the reference link for more information.