Vulnerabilities (CVE)

Filtered by vendor Huawei Subscribe
Filtered by product Fusioncompute
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-37106 1 Huawei 1 Fusioncompute 2022-05-03 9.0 HIGH 7.2 HIGH
There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system.
CVE-2021-37102 1 Huawei 1 Fusioncompute 2021-11-26 9.0 HIGH 8.8 HIGH
There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system. Affected product versions include: FusionCompute 6.0.0, 6.3.0, 6.3.1, 6.5.0, 6.5.1, 8.0.0.
CVE-2021-37105 1 Huawei 1 Fusioncompute 2021-10-06 4.3 MEDIUM 7.5 HIGH
There is an improper file upload control vulnerability in FusionCompute 6.5.0, 6.5.1 and 8.0.0. Due to the improper verification of file to be uploaded and does not strictly restrict the file access path, attackers may upload malicious files to the device, resulting in the service abnormal.
CVE-2020-9078 1 Huawei 1 Fusioncompute 2021-07-21 4.6 MEDIUM 7.8 HIGH
FusionCompute 8.0.0 have local privilege escalation vulnerability. A local, authenticated attacker could perform specific operations to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege and compromise the service.
CVE-2020-9228 1 Huawei 1 Fusioncompute 2021-07-21 5.0 MEDIUM 7.5 HIGH
FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, attackers may exploit this vulnerability to obtain certain information.
CVE-2020-9242 1 Huawei 1 Fusioncompute 2021-07-21 6.5 MEDIUM 8.8 HIGH
FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful exploit could allow an authenticated attacker to launch a command injection attack.
CVE-2020-9116 1 Huawei 1 Fusioncompute 2020-12-02 6.5 MEDIUM 7.2 HIGH
Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to exploit this vulnerability. Due to insufficient verification, this could be exploited to cause the attackers to obtain higher privilege.
CVE-2020-9114 1 Huawei 1 Fusioncompute 2020-12-02 7.2 HIGH 7.8 HIGH
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may access some specific files and get the administrator privilege in the affected products. Successful exploit will cause privilege escalation.