ID

VAR-201711-0949


CVE

CVE-2017-8188


TITLE

FusionSphere OpenStack Command injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-010568

DESCRIPTION

FusionSphere OpenStack V100R006C00SPC102(NFV)has a command injection vulnerability. Due to lack of validation, an attacker with high privilege may inject malicious code into some module of the affected products, causing code execution. FusionSphere OpenStack Contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Huawei FusionSphere OpenStack is prone to a command-injection vulnerability. Huawei FusionSphere OpenStack is a set of cloud platform software for FusionSphere (cloud operating system) of Huawei in China in ICT scenarios. The vulnerability is caused by the insufficient verification of external input in the program

Trust: 1.98

sources: NVD: CVE-2017-8188 // JVNDB: JVNDB-2017-010568 // BID: 102326 // VULHUB: VHN-116391

AFFECTED PRODUCTS

vendor:huaweimodel:fusionsphere openstackscope:eqversion:v100r006c00spc102\(nfv\)

Trust: 1.6

vendor:huaweimodel:fusionsphere openstackscope:eqversion:v100r006c00spc102 (nfv)

Trust: 0.8

vendor:huaweimodel:fusionsphere openstack v100r006c00spc102scope: - version: -

Trust: 0.3

vendor:huaweimodel:fusionsphere openstack v100r006c10spc300scope:neversion: -

Trust: 0.3

sources: BID: 102326 // JVNDB: JVNDB-2017-010568 // CNNVD: CNNVD-201711-950 // NVD: CVE-2017-8188

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-8188
value: HIGH

Trust: 1.0

NVD: CVE-2017-8188
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201711-950
value: MEDIUM

Trust: 0.6

VULHUB: VHN-116391
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-8188
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-116391
severity: MEDIUM
baseScore: 6.5
vectorString: AV:N/AC:L/AU:S/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-8188
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-116391 // JVNDB: JVNDB-2017-010568 // CNNVD: CNNVD-201711-950 // NVD: CVE-2017-8188

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.9

sources: VULHUB: VHN-116391 // JVNDB: JVNDB-2017-010568 // NVD: CVE-2017-8188

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201711-950

TYPE

command injection

Trust: 0.6

sources: CNNVD: CNNVD-201711-950

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-010568

PATCH

title:huawei-sa-20171018-01-fusionsphereurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171018-01-fusionsphere-en

Trust: 0.8

title:Huawei FusionSphere OpenStack Fixes for command injection vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=76660

Trust: 0.6

sources: JVNDB: JVNDB-2017-010568 // CNNVD: CNNVD-201711-950

EXTERNAL IDS

db:NVDid:CVE-2017-8188

Trust: 2.8

db:JVNDBid:JVNDB-2017-010568

Trust: 0.8

db:CNNVDid:CNNVD-201711-950

Trust: 0.7

db:BIDid:102326

Trust: 0.4

db:VULHUBid:VHN-116391

Trust: 0.1

sources: VULHUB: VHN-116391 // BID: 102326 // JVNDB: JVNDB-2017-010568 // CNNVD: CNNVD-201711-950 // NVD: CVE-2017-8188

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171018-01-fusionsphere-en

Trust: 2.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-8188

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-8188

Trust: 0.8

url:http://www.huawei.com

Trust: 0.3

sources: VULHUB: VHN-116391 // BID: 102326 // JVNDB: JVNDB-2017-010568 // CNNVD: CNNVD-201711-950 // NVD: CVE-2017-8188

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 102326

SOURCES

db:VULHUBid:VHN-116391
db:BIDid:102326
db:JVNDBid:JVNDB-2017-010568
db:CNNVDid:CNNVD-201711-950
db:NVDid:CVE-2017-8188

LAST UPDATE DATE

2025-04-20T23:42:04.167000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-116391date:2017-12-08T00:00:00
db:BIDid:102326date:2017-10-18T00:00:00
db:JVNDBid:JVNDB-2017-010568date:2017-12-19T00:00:00
db:CNNVDid:CNNVD-201711-950date:2017-11-23T00:00:00
db:NVDid:CVE-2017-8188date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-116391date:2017-11-22T00:00:00
db:BIDid:102326date:2017-10-18T00:00:00
db:JVNDBid:JVNDB-2017-010568date:2017-12-19T00:00:00
db:CNNVDid:CNNVD-201711-950date:2017-11-23T00:00:00
db:NVDid:CVE-2017-8188date:2017-11-22T19:29:04.553