Information Exposure Vulnerability in FusionSphere OpenStack by Huawei
CVE-2017-2720
5.3MEDIUM
Summary
FusionSphere OpenStack V100R006C00 is susceptible to an information exposure vulnerability that arises from the use of hard-coded cryptographic keys for message encryption among its components. This design flaw significantly threatens the confidentiality of the encrypted messages, allowing potential attackers to recover sensitive data. Organizations using this affected version should take immediate steps to mitigate the risks associated with this vulnerability.
Affected Version(s)
FusionSphere OpenStack V100R006C00
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved