First published: Wed Nov 22 2017(Updated: )
The FusionSphere OpenStack V100R006C00SPC102(NFV) has a command injection vulnerability. Due to the insufficient input validation on one port, an authenticated, local attacker may exploit the vulnerability to gain root privileges by sending message with malicious commands.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei FusionSphere OpenStack | =v100r006c00spc102\(nfv\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8193 is a command injection vulnerability in FusionSphere OpenStack V100R006C00SPC102(NFV) that allows an authenticated, local attacker to gain root privileges.
The vulnerability is due to insufficient input validation on one port, allowing an attacker to send messages with malicious commands and gain root privileges.
CVE-2017-8193 has a severity score of 8, which is considered high.
FusionSphere OpenStack V100R006C00SPC102(NFV) is affected by CVE-2017-8193.
To fix CVE-2017-8193, update to the latest version of FusionSphere OpenStack V100R006C00SPC102(NFV) provided by Huawei.