Improper Authorization in FusionSphere OpenStack by Huawei
CVE-2017-8192

7.8HIGH

Key Information:

Vendor
McAfee
Vendor
CVE Published:
22 November 2017

Summary

The FusionSphere OpenStack V100R006C00 is affected by an improper authorization vulnerability, which allows an attacker with low privileges to exploit access controls. By leveraging this flaw, they can gain unauthorized operation authority to specific directories, leading to potential privilege escalation and unauthorized access to critical resources.

Affected Version(s)

FusionSphere OpenStack V100R006C00

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.