Huawei / Fusionsphere Openstack
21 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-9079 | FusionSphere OpenStack 8.0.0 have a protection mechanism failure vulnerability. The product incorrectly uses a protection mechanism. An attacker has to find a… | HIGH | 8.8 | Aug 11, 2020 |
| CVE-2020-9225 | FusionSphere OpenStack 6.5.1 have an improper permissions management vulnerability. The software does not correctly perform a privilege assignment when an acto… | HIGH | 7.8 | Jun 18, 2020 |
| CVE-2018-7977 | There is an information leakage vulnerability on several Huawei products. Due to insufficient communication protection for specific services, a remote, unautho… | HIGH | 7.5 | Nov 27, 2018 |
| CVE-2017-8187 | Huawei FusionSphere OpenStack V100R006C00SPC102(NFV) has a privilege escalation vulnerability. Due to improper privilege restrictions, an attacker with high pr… | HIGH | 7.2 | Mar 20, 2018 |
| CVE-2017-15321 | Huawei FusionSphere OpenStack V100R006C000SPC102 (NFV) has an information leak vulnerability due to the use of a low version transmission protocol by default.… | LOW | 3.7 | Dec 22, 2017 |
| CVE-2017-8195 | The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authenticated, r… | HIGH | 8.8 | Nov 22, 2017 |
| CVE-2017-8194 | The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authenticated, r… | HIGH | 8.8 | Nov 22, 2017 |
| CVE-2017-8193 | The FusionSphere OpenStack V100R006C00SPC102(NFV) has a command injection vulnerability. Due to the insufficient input validation on one port, an authenticated… | HIGH | 8.0 | Nov 22, 2017 |
| CVE-2017-8192 | FusionSphere OpenStack V100R006C00 has an improper authorization vulnerability. Due to improper authorization, an attacker with low privilege may exploit this… | HIGH | 7.8 | Nov 22, 2017 |
| CVE-2017-8191 | FusionSphere OpenStack V100R006C00SPC102(NFV)has a week cryptographic algorithm vulnerability. Attackers may exploit the vulnerability to crack the cipher text… | MEDIUM | 5.9 | Nov 22, 2017 |
| CVE-2017-8190 | FusionSphere OpenStack V100R006C00SPC102(NFV)has an improper verification of cryptographic signature vulnerability. The software does not verify the cryptograp… | MEDIUM | 6.7 | Nov 22, 2017 |
| CVE-2017-8189 | FusionSphere OpenStack V100R006C00SPC102(NFV)has a path traversal vulnerability. Due to insufficient path validation, an attacker with high privilege may explo… | MEDIUM | 6.0 | Nov 22, 2017 |
| CVE-2017-8188 | FusionSphere OpenStack V100R006C00SPC102(NFV)has a command injection vulnerability. Due to lack of validation, an attacker with high privilege may inject malic… | HIGH | 7.2 | Nov 22, 2017 |
| CVE-2017-8168 | FusionSphere OpenStack with software V100R006C00SPC102(NFV) and V100R006C10 have an information leak vulnerability. Due to an incorrect configuration item, the… | MEDIUM | 4.3 | Nov 22, 2017 |
| CVE-2017-8135 | The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP… | HIGH | 8.8 | Nov 22, 2017 |
| CVE-2017-8134 | The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP… | HIGH | 8.8 | Nov 22, 2017 |
| CVE-2017-8132 | The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP… | HIGH | 8.8 | Nov 22, 2017 |
| CVE-2017-8131 | The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP… | HIGH | 8.8 | Nov 22, 2017 |
| CVE-2017-2720 | FusionSphere OpenStack V100R006C00 has an information exposure vulnerability. The software uses hard-coded cryptographic key to encrypt messages between certai… | MEDIUM | 5.3 | Nov 22, 2017 |
| CVE-2017-2719 | FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one p… | HIGH | 8.8 | Nov 22, 2017 |
| CVE-2017-2718 | FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one p… | HIGH | 8.8 | Nov 22, 2017 |
| CVE-2017-2714 | The GaussDB in FusionSphere OpenStack V100R005C10SPC705 and earlier versions has a buffer overflow vulnerability. An authenticated attacker on the LAN can expl… | HIGH | 8.0 | Nov 22, 2017 |
Showing 1 to 21 of 21 CVEs