Command Injection Vulnerability in Huawei FusionCompute Software
CVE-2020-9116

7.2HIGH

Key Information:

Vendor
Huawei
Vendor
CVE Published:
1 December 2020

Summary

Huawei FusionCompute versions 6.5.1 and 8.0.0 are susceptible to a command injection vulnerability. An authenticated remote attacker can exploit this flaw by sending specifically crafted requests, which may lead to inadequate verification processes. This oversight allows attackers to potentially escalate their privileges within the system, posing a significant security risk. Organizations using these versions of FusionCompute should review their configurations and apply necessary updates to mitigate this vulnerability. For further details, please visit the Huawei PSIRT advisory.

Affected Version(s)

FusionCompute 6.5.1,8.0.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.