CVE-2020-9242: Command Injection
Published Aug 17, 2020
·Updated
FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful exploit could allow an authenticated attacker to launch a command injection attack.
Affected Software
1 affected component
huawei FusionCompute=8.0.0
Event History
Aug 17, 2020
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-9242?
CVE-2020-9242 is a command injection vulnerability in Huawei FusionCompute 8.0.0.
2
How does the vulnerability in FusionCompute 8.0.0 occur?
The vulnerability occurs due to insufficient validation of certain parameters post from the user.
3
What is the severity of CVE-2020-9242?
The severity of CVE-2020-9242 is high with a CVSS score of 8.8.
4
How can an attacker exploit CVE-2020-9242?
An authenticated attacker can launch a command injection attack by exploiting CVE-2020-9242.
5
Is there a fix available for CVE-2020-9242?
It is recommended to update to a patched version of Huawei FusionCompute to fix the CVE-2020-9242 vulnerability.