CVE-2017-8190
Summary
| CVE | CVE-2017-8190 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-11-22 19:29:00 UTC |
| Updated | 2017-12-08 19:04:00 UTC |
| Description | FusionSphere OpenStack V100R006C00SPC102(NFV)has an improper verification of cryptographic signature vulnerability. The software does not verify the cryptographic signature. An attacker with high privilege may exploit this vulnerability to inject malicious software. |
Risk And Classification
Problem Types: CWE-347
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Huawei | Fusionsphere Openstack | v100r006c00spc102(nfv) | All | All | All |
| Operating System | Huawei | Fusionsphere Openstack | v100r006c00spc102\(nfv\) | All | All | All |
| Operating System | Huawei | Fusionsphere Openstack | v100r006c00spc102\(nfv\) | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Multiple Vulnerabilities in FusionSphere OpenStack | CONFIRM | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.