ZeroHour

CVE-2017-2718

CVSS 3.1
8.8 high
EPSS
<1%p58
Published
()
Modified
Description

FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.

Vendors
huawei
Products
fusionsphere openstack
Weakness
CWE-77
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.