CVE-2021-37106: Command Injection
Published Sep 28, 2021
·Updated
There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system.
Affected Software
4 affected components
huawei FusionCompute=6.3.0
huawei FusionCompute=6.3.1
huawei FusionCompute=6.5.0
huawei FusionCompute=8.0.0
Event History
Sep 28, 2021
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this command injection vulnerability?
The vulnerability ID is CVE-2021-37106.
2
What is the severity level of CVE-2021-37106?
CVE-2021-37106 has a severity level of 7.2 (critical).
3
What software versions are affected by CVE-2021-37106?
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, and 8.0.0 are affected by CVE-2021-37106.
4
Are there any available fixes for CVE-2021-37106?
The reference link provided by Huawei contains information about available fixes for CVE-2021-37106.
5
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2021-37106?
CVE-2021-37106 is associated with CWE-77.