CVE-2020-9116
Summary
| CVE | CVE-2020-9116 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-01 00:15:00 UTC |
| Updated | 2020-12-02 20:54:00 UTC |
| Description | Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to exploit this vulnerability. Due to insufficient verification, this could be exploited to cause the attackers to obtain higher privilege. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Huawei | Fusioncompute | 6.5.1 | All | All | All |
| Application | Huawei | Fusioncompute | 8.0.0 | All | All | All |
| Application | Huawei | Fusioncompute | 6.5.1 | All | All | All |
| Application | Huawei | Fusioncompute | 8.0.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - Command Injection Vulnerability in Huawei FusionCompute Product | MISC | www.huawei.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.