Improper Cryptographic Signature Verification in FusionSphere OpenStack by Huawei
CVE-2017-8190

6.7MEDIUM

Key Information:

Vendor
McAfee
Vendor
CVE Published:
15 November 2017

Summary

Huawei's FusionSphere OpenStack is susceptible to a vulnerability that results from improper verification of cryptographic signatures. This security flaw allows an attacker with elevated privileges to potentially exploit this weakness to inject malicious software into the system. The inadequate signature validation poses a significant risk, enabling unauthorized access and manipulation of the software's functionality.

Affected Version(s)

FusionSphere OpenStack V100R006C00SPC102(NFV)

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.