René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

109 lines
3.5 KiB
JSON

{
"id": "CVE-2017-8158",
"sourceIdentifier": "psirt@huawei.com",
"published": "2017-11-22T19:29:03.647",
"lastModified": "2019-10-03T00:03:26.223",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "FusionCompute V100R005C00 and V100R005C10 have an improper authorization vulnerability due to improper permission settings for a certain file on the host machine. An authenticated attacker could create a large number of virtual machine (VM) processes to exhaust system resources. Successful exploit could make new VMs unavailable."
},
{
"lang": "es",
"value": "FusionCompute V100R005C00 y V100R005C10 tiene una vulnerabilidad de autorizaci\u00f3n incorrecta debido a una configuraci\u00f3n de permisos incorrecta para un archivo determinado en la m\u00e1quina host. Un atacante autenticado podr\u00eda crear un gran n\u00famero de procesos de m\u00e1quina virtual para agotar los recursos del sistema. Un exploit exitoso podr\u00eda hacer que las nuevas m\u00e1quinas virtuales no est\u00e9n disponibles."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.0,
"impactScore": 4.0
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:C",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "COMPLETE",
"baseScore": 4.9
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 3.9,
"impactScore": 6.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-732"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:fusioncompute:v100r005c00:*:*:*:*:*:*:*",
"matchCriteriaId": "8F40C57C-331D-4ED6-98A2-47AB5272EB4C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:huawei:fusioncompute:v100r005c10:*:*:*:*:*:*:*",
"matchCriteriaId": "87FBF1BD-8FB0-4C5B-A05E-1FD26F4C4466"
}
]
}
]
}
],
"references": [
{
"url": "http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20170927-01-dos-en",
"source": "psirt@huawei.com",
"tags": [
"Vendor Advisory"
]
}
]
}