CVE Database
/

CVE-2017-8135

Back to search

CVE-2017-8135

Published: Nov 22, 2017

Modified: Sep 16, 2024

PUBLISHED

Description

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.

VendorProductVersions

Huawei Technologies Co., Ltd.

FusionSphere OpenStack

affected
V100R006C00 and V100R006C10

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now