ID

VAR-201711-1011


CVE

CVE-2017-8196


TITLE

FusionSphere Authorization vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-010576

DESCRIPTION

FusionSphere V100R006C00SPC102(NFV) has an incorrect authorization vulnerability. An authenticated attacker could execute commands that he/she should have had no permission to perform, thereby querying, modifying, and deleting certain service data and making the service unavailable. FusionSphere Contains an authorization vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Huawei FusionSphere is a cloud operating system developed by China's Huawei (Huawei) based on the OpenStack framework. The system provides virtualization functions, resource pool management and cloud basic service tools, etc. Security vulnerabilities exist in Huawei FusionSphere V100R006C00SPC102(NFV)

Trust: 1.71

sources: NVD: CVE-2017-8196 // JVNDB: JVNDB-2017-010576 // VULHUB: VHN-116399

AFFECTED PRODUCTS

vendor:huaweimodel:fusionspherescope:eqversion:v100r006c00spc102\(nfv\)

Trust: 1.6

vendor:huaweimodel:fusionspherescope:eqversion:v100r006c00spc102 (nfv)

Trust: 0.8

sources: JVNDB: JVNDB-2017-010576 // CNNVD: CNNVD-201711-942 // NVD: CVE-2017-8196

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-8196
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-8196
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201711-942
value: MEDIUM

Trust: 0.6

VULHUB: VHN-116399
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-8196
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-116399
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-8196
baseSeverity: MEDIUM
baseScore: 4.2
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: LOW
exploitabilityScore: 0.8
impactScore: 3.4
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-116399 // JVNDB: JVNDB-2017-010576 // CNNVD: CNNVD-201711-942 // NVD: CVE-2017-8196

PROBLEMTYPE DATA

problemtype:CWE-863

Trust: 1.1

problemtype:CWE-285

Trust: 0.9

sources: VULHUB: VHN-116399 // JVNDB: JVNDB-2017-010576 // NVD: CVE-2017-8196

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201711-942

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201711-942

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-010576

PATCH

title:huawei-sa-20170913-01-fusionsphereurl:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170913-01-fusionsphere-en

Trust: 0.8

title:Huawei FusionSphere Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=76652

Trust: 0.6

sources: JVNDB: JVNDB-2017-010576 // CNNVD: CNNVD-201711-942

EXTERNAL IDS

db:NVDid:CVE-2017-8196

Trust: 2.5

db:JVNDBid:JVNDB-2017-010576

Trust: 0.8

db:CNNVDid:CNNVD-201711-942

Trust: 0.7

db:VULHUBid:VHN-116399

Trust: 0.1

sources: VULHUB: VHN-116399 // JVNDB: JVNDB-2017-010576 // CNNVD: CNNVD-201711-942 // NVD: CVE-2017-8196

REFERENCES

url:http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170913-01-fusionsphere-en

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-8196

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-8196

Trust: 0.8

sources: VULHUB: VHN-116399 // JVNDB: JVNDB-2017-010576 // CNNVD: CNNVD-201711-942 // NVD: CVE-2017-8196

SOURCES

db:VULHUBid:VHN-116399
db:JVNDBid:JVNDB-2017-010576
db:CNNVDid:CNNVD-201711-942
db:NVDid:CVE-2017-8196

LAST UPDATE DATE

2025-04-20T23:25:54.179000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-116399date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2017-010576date:2017-12-19T00:00:00
db:CNNVDid:CNNVD-201711-942date:2019-10-23T00:00:00
db:NVDid:CVE-2017-8196date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:VULHUBid:VHN-116399date:2017-11-22T00:00:00
db:JVNDBid:JVNDB-2017-010576date:2017-12-19T00:00:00
db:CNNVDid:CNNVD-201711-942date:2017-11-23T00:00:00
db:NVDid:CVE-2017-8196date:2017-11-22T19:29:04.867