Incorrect permission assignment for critical resource in FusionCompute - CVE-2017-8158
Published: November 22, 2017 / Updated: August 8, 2020
FusionCompute
Detailed vulnerability description
The vulnerability allows a local authenticated user to a crash the entire system.
FusionCompute V100R005C00 and V100R005C10 have an improper authorization vulnerability due to improper permission settings for a certain file on the host machine. An authenticated attacker could create a large number of virtual machine (VM) processes to exhaust system resources. Successful exploit could make new VMs unavailable.