Command Injection Vulnerability in FusionCompute by Huawei
CVE-2021-37102
8.8HIGH
Summary
A command injection vulnerability exists in the CMA service module of Huawei's FusionCompute when handling the default certificate file. The issue arises due to improper validation of user input, allowing an attacker to execute arbitrary commands on the affected system. This vulnerability affects multiple versions of FusionCompute, including 6.0.0 and 8.0.0, potentially leading to unauthorized access and manipulation of system operations.
Affected Version(s)
FusionCompute 6.0.0,6.3.0,6.3.1,6.5.0,6.5.1,8.0.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved