First published: Wed Nov 22 2017(Updated: )
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei FusionSphere OpenStack | =v100r006c00 | |
Huawei FusionSphere OpenStack | =v100r006c10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8135 is a command injection vulnerability in FusionSphere OpenStack with software V100R006C00 and V100R006C10.
CVE-2017-8135 has a severity rating of 8.8 (high).
CVE-2017-8135 allows an unauthenticated attacker to gain root privileges by exploiting the command injection vulnerability in Huawei FusionSphere OpenStack with software V100R006C00 and V100R006C10.
To fix CVE-2017-8135, users should apply the necessary patches and updates provided by Huawei.
You can find more information about CVE-2017-8135 in the following references: [Huawei Security Advisory](http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170531-01-openstack-en) and [SecurityFocus](http://www.securityfocus.com/bid/102262).