SB2017112215 - Multiple vulnerabilities in Huawei FusionSphere OpenStack



SB2017112215 - Multiple vulnerabilities in Huawei FusionSphere OpenStack

Published: November 22, 2017 Updated: August 8, 2020

Security Bulletin ID SB2017112215
Severity
High
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 secuirty vulnerabilities.


1) Command Injection (CVE-ID: CVE-2017-8131)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.


2) Command Injection (CVE-ID: CVE-2017-8132)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.


3) Command Injection (CVE-ID: CVE-2017-8134)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.


4) Command Injection (CVE-ID: CVE-2017-8135)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.


5) Command Injection (CVE-ID: CVE-2017-2718)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.


Remediation

Install update from vendor's website.