First published: Wed Nov 22 2017(Updated: )
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei FusionSphere OpenStack | =v100r006c00 | |
Huawei FusionSphere OpenStack | =v100r006c10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-8134 is high with a CVSS score of 8.8.
The affected software for CVE-2017-8134 is Huawei FusionSphere OpenStack with software versions V100R006C00 and V100R006C10.
CVE-2017-8134 exploits a command injection vulnerability due to insufficient input validation on four TCP listening ports, allowing an unauthenticated attacker to gain root privileges by sending malicious messages.
No, CVE-2017-8134 can be exploited by an unauthenticated attacker.
To fix CVE-2017-8134, it is recommended to apply the necessary security patches or updates provided by Huawei.