109 lines
3.4 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2017-2718",
"sourceIdentifier": "psirt@huawei.com",
"published": "2017-11-22T19:29:01.287",
"lastModified": "2020-07-28T14:51:03.847",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands."
},
{
"lang": "es",
"value": "FusionSphere OpenStack con software V100R006C00 y V100R006C10RC2 tiene dos vulnerabilidades de inyecci\u00f3n de comandos debido a la validaci\u00f3n de entradas insuficiente en un puerto. Un atacante puede explotar las vulnerabilidades para obtener privilegios root mediante el env\u00edo de algunos mensajes con comandos maliciosos."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:A/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "ADJACENT_NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 8.3
},
"baseSeverity": "HIGH",
"exploitabilityScore": 6.5,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-77"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:huawei:fusionsphere_openstack:v100r006c00:*:*:*:*:*:*:*",
"matchCriteriaId": "4CB1DB1F-5CAC-486C-AECF-59E9793F50AB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:huawei:fusionsphere_openstack:v100r006c10:rc2:*:*:*:*:*:*",
"matchCriteriaId": "E30BCE00-531D-43BA-932C-ABA73E16DB4D"
}
]
}
]
}
],
"references": [
{
"url": "http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170823-01-openstack-en",
"source": "psirt@huawei.com",
"tags": [
"Vendor Advisory"
]
}
]
}