Huawei
Huawei Fusionsphere Openstack: vulnerabilidades y CVE
Huawei Fusionsphere Openstack tiene 21 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-9079 | Alta (8.8) | 0.38% | — | 11 ago 2020 | FusionSphere OpenStack 8.0.0 have a protection mechanism failure vulnerability. The product incorrectly uses a protection mechanism. An attacker has to find a way to exploit the vulnerability to conduct directed attacks… |
| CVE-2020-9225 | Alta (7.8) | 0.20% | — | 18 jun 2020 | FusionSphere OpenStack 6.5.1 have an improper permissions management vulnerability. The software does not correctly perform a privilege assignment when an actor attempts to perform an action. Successful exploit could… |
| CVE-2018-7977 | Alta (7.5) | 0.98% | — | 27 nov 2018 | There is an information leakage vulnerability on several Huawei products. Due to insufficient communication protection for specific services, a remote, unauthorized attacker can exploit this vulnerability to connect to… |
| CVE-2017-15321 | Baja (3.7) | 0.61% | — | 22 dic 2017 | Huawei FusionSphere OpenStack V100R006C000SPC102 (NFV) has an information leak vulnerability due to the use of a low version transmission protocol by default. An attacker could intercept packets transferred by a target… |
| CVE-2017-8195 | Alta (8.8) | 1.2% | — | 22 nov 2017 | The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authenticated, remote attacker may exploit the vulnerability to execute more… |
| CVE-2017-8194 | Alta (8.8) | 1.2% | — | 22 nov 2017 | The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authenticated, remote attacker may exploit the vulnerability to execute more… |
| CVE-2017-8193 | Alta (8) | 0.86% | — | 22 nov 2017 | The FusionSphere OpenStack V100R006C00SPC102(NFV) has a command injection vulnerability. Due to the insufficient input validation on one port, an authenticated, local attacker may exploit the vulnerability to gain root… |
| CVE-2017-8192 | Alta (7.8) | 0.22% | — | 22 nov 2017 | FusionSphere OpenStack V100R006C00 has an improper authorization vulnerability. Due to improper authorization, an attacker with low privilege may exploit this vulnerability to obtain the operation authority of some… |
| CVE-2017-8191 | Media (5.9) | 0.60% | — | 22 nov 2017 | FusionSphere OpenStack V100R006C00SPC102(NFV)has a week cryptographic algorithm vulnerability. Attackers may exploit the vulnerability to crack the cipher text and cause information leak on the transmission links. |
| CVE-2017-8190 | Media (6.7) | 0.19% | — | 22 nov 2017 | FusionSphere OpenStack V100R006C00SPC102(NFV)has an improper verification of cryptographic signature vulnerability. The software does not verify the cryptographic signature. An attacker with high privilege may exploit… |
| CVE-2017-8189 | Media (6) | 0.28% | — | 22 nov 2017 | FusionSphere OpenStack V100R006C00SPC102(NFV)has a path traversal vulnerability. Due to insufficient path validation, an attacker with high privilege may exploit this vulnerability to cover some files, causing services… |
| CVE-2017-8188 | Alta (7.2) | 1.7% | — | 22 nov 2017 | FusionSphere OpenStack V100R006C00SPC102(NFV)has a command injection vulnerability. Due to lack of validation, an attacker with high privilege may inject malicious code into some module of the affected products, causing… |
| CVE-2017-8168 | Media (4.3) | 0.27% | — | 22 nov 2017 | FusionSphere OpenStack with software V100R006C00SPC102(NFV) and V100R006C10 have an information leak vulnerability. Due to an incorrect configuration item, the information transmitted by a transmission channel is not… |
| CVE-2017-8135 | Alta (8.8) | 1.4% | — | 22 nov 2017 | The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit… |
| CVE-2017-8134 | Alta (8.8) | 1.4% | — | 22 nov 2017 | The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit… |
| CVE-2017-8132 | Alta (8.8) | 1.4% | — | 22 nov 2017 | The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit… |
| CVE-2017-8131 | Alta (8.8) | 1.4% | — | 22 nov 2017 | The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit… |
| CVE-2017-2720 | Media (5.3) | 0.71% | — | 22 nov 2017 | FusionSphere OpenStack V100R006C00 has an information exposure vulnerability. The software uses hard-coded cryptographic key to encrypt messages between certain components, which significantly increases the possibility… |
| CVE-2017-2719 | Alta (8.8) | 0.92% | — | 22 nov 2017 | FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain… |
| CVE-2017-2718 | Alta (8.8) | 0.91% | — | 22 nov 2017 | FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain… |
| CVE-2017-2714 | Alta (8) | 0.52% | — | 22 nov 2017 | The GaussDB in FusionSphere OpenStack V100R005C10SPC705 and earlier versions has a buffer overflow vulnerability. An authenticated attacker on the LAN can exploit this vulnerability to execute arbitrary code or cause a… |