Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to exploit this vulnerability. Due to insufficient verification, this could be exploited to cause the attackers to obtain higher privilege.
References
Link | Resource |
---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20201118-01-fusioncompute-en | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: huawei
Published: 2020-11-30T23:53:58
Updated: 2020-11-30T23:53:58
Reserved: 2020-02-18T00:00:00
Link: CVE-2020-9116
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-12-01T00:15:11.507
Modified: 2020-12-02T20:54:42.853
Link: CVE-2020-9116
JSON object: View
Redhat Information
No data.
CWE