{"api_version":"1","generated_at":"2026-07-23T06:10:43+00:00","cve":"CVE-2017-2719","urls":{"html":"https://cve.report/CVE-2017-2719","api":"https://cve.report/api/cve/CVE-2017-2719.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-2719","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-2719"},"summary":{"title":"CVE-2017-2719","description":"FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.","state":"PUBLISHED","assigner":"huawei","published_at":"2017-11-22 19:29:01","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-77","Command Injection"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"8.8","severity":"HIGH","vector":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"8.3","severity":"","vector":"AV:A/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:A/AC:L/Au:N/C:C/I:C/A:C","baseScore":8.3,"accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170823-01-openstack-en","name":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170823-01-openstack-en","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory - Two Command Injection Vulnerabilities in The FusionSphere OpenStack","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-2719","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-2719","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Huawei Technologies Co., Ltd.","product":"FusionSphere OpenStack","version":"affected V100R006C00&#xa3","platforms":[]},{"source":"CNA","vendor":"Huawei Technologies Co., Ltd.","product":"FusionSphere OpenStack","version":"affected &#xac","platforms":[]},{"source":"CNA","vendor":"Huawei Technologies Co., Ltd.","product":"FusionSphere OpenStack","version":"affected V100R006C10RC2","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"2719","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"huawei","cpe5":"fusionsphere_openstack","cpe6":"v100r006c00","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"2719","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"huawei","cpe5":"fusionsphere_openstack","cpe6":"v100r006c10rc2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"2719","cve":"CVE-2017-2719","epss":"0.004450000","percentile":"0.635920000","score_date":"2026-05-14","updated_at":"2026-05-15 00:08:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T14:02:07.626Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170823-01-openstack-en"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"FusionSphere OpenStack","vendor":"Huawei Technologies Co., Ltd.","versions":[{"status":"affected","version":"V100R006C00&#xa3"},{"status":"affected","version":"&#xac"},{"status":"affected","version":"V100R006C10RC2"}]}],"datePublic":"2017-11-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands."}],"problemTypes":[{"descriptions":[{"description":"Command Injection","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-11-22T18:57:01.000Z","orgId":"25ac1063-e409-4190-8079-24548c77ea2e","shortName":"huawei"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170823-01-openstack-en"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@huawei.com","DATE_PUBLIC":"2017-11-15T00:00:00","ID":"CVE-2017-2719","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"FusionSphere OpenStack","version":{"version_data":[{"version_value":"V100R006C00&#xa3"},{"version_value":"&#xac"},{"version_value":"V100R006C10RC2"}]}}]},"vendor_name":"Huawei Technologies Co., Ltd."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Command Injection"}]}]},"references":{"reference_data":[{"name":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170823-01-openstack-en","refsource":"CONFIRM","url":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170823-01-openstack-en"}]}}}},"cveMetadata":{"assignerOrgId":"25ac1063-e409-4190-8079-24548c77ea2e","assignerShortName":"huawei","cveId":"CVE-2017-2719","datePublished":"2017-11-22T19:00:00.000Z","dateReserved":"2016-12-01T00:00:00.000Z","dateUpdated":"2024-09-16T21:58:25.063Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-11-22 19:29:01","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-77","Command Injection"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:A/AC:L/Au:N/C:C/I:C/A:C","baseScore":8.3,"accessVector":"ADJACENT_NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.5,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:fusionsphere_openstack:v100r006c00:*:*:*:*:*:*:*","matchCriteriaId":"4CB1DB1F-5CAC-486C-AECF-59E9793F50AB"},{"vulnerable":true,"criteria":"cpe:2.3:o:huawei:fusionsphere_openstack:v100r006c10rc2:*:*:*:*:*:*:*","matchCriteriaId":"D748184C-0EC7-45B2-A19E-D6CC1B0A116F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"2719","Ordinal":"1","Title":"CVE-2017-2719","CVE":"CVE-2017-2719","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"2719","Ordinal":"1","NoteData":"FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.","Type":"Description","Title":"CVE-2017-2719"},{"CveYear":"2017","CveId":"2719","Ordinal":"2","NoteData":"2017-11-22","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"2719","Ordinal":"3","NoteData":"2017-11-22","Type":"Other","Title":"Modified"}]}}}