Command Injection in FusionSphere OpenStack - CVE-2017-8132

 

Command Injection in FusionSphere OpenStack - CVE-2017-8132

Published: November 22, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU37880
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8132
CWE-ID: CWE-77
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.


Affected software

FusionSphere OpenStack

How to mitigate CVE-2017-8132

Install update from vendor's website.


External References

Related Security Bulletins