CVE-2017-8158: Medium severity huawei fusioncompute firmware vulnerability
Published Nov 22, 2017
·Updated
FusionCompute V100R005C00 and V100R005C10 have an improper authorization vulnerability due to improper permission settings for a certain file on the host machine. An authenticated attacker could create a large number of virtual machine (VM) processes to exhaust system resources. Successful exploit could make new VMs unavailable.
Affected Software
2 affected components
huawei FusionCompute=v100r005c00
huawei FusionCompute=v100r005c10
Event History
Nov 22, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this FusionCompute vulnerability?
The vulnerability ID for this FusionCompute vulnerability is CVE-2017-8158.
2
What is the severity level of CVE-2017-8158?
The severity level of CVE-2017-8158 is medium.
3
How can an attacker exploit CVE-2017-8158?
An attacker can exploit CVE-2017-8158 by creating a large number of virtual machine processes to exhaust system resources.
4
Which versions of FusionCompute are affected by CVE-2017-8158?
FusionCompute V100R005C00 and V100R005C10 are affected by CVE-2017-8158.
5
How can I fix CVE-2017-8158?
To fix CVE-2017-8158, users should apply the necessary patches or updates provided by Huawei.