{"api_version":"1","generated_at":"2026-07-23T09:54:52+00:00","cve":"CVE-2017-8190","urls":{"html":"https://cve.report/CVE-2017-8190","api":"https://cve.report/api/cve/CVE-2017-8190.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-8190","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-8190"},"summary":{"title":"CVE-2017-8190","description":"FusionSphere OpenStack V100R006C00SPC102(NFV)has an improper verification of cryptographic signature vulnerability. The software does not verify the cryptographic signature. An attacker with high privilege may exploit this vulnerability to inject malicious software.","state":"PUBLIC","assigner":"psirt@huawei.com","published_at":"2017-11-22 19:29:00","updated_at":"2017-12-08 19:04:00"},"problem_types":["CWE-347"],"metrics":[],"references":[{"url":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171018-01-fusionsphere-en","name":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171018-01-fusionsphere-en","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Advisory - Multiple Vulnerabilities in FusionSphere OpenStack","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-8190","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-8190","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"8190","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"huawei","cpe5":"fusionsphere_openstack","cpe6":"v100r006c00spc102(nfv)","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"8190","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"huawei","cpe5":"fusionsphere_openstack","cpe6":"v100r006c00spc102\\(nfv\\)","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"8190","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"huawei","cpe5":"fusionsphere_openstack","cpe6":"v100r006c00spc102\\(nfv\\)","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@huawei.com","DATE_PUBLIC":"2017-11-15T00:00:00","ID":"CVE-2017-8190","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"FusionSphere OpenStack","version":{"version_data":[{"version_value":"V100R006C00SPC102(NFV)"}]}}]},"vendor_name":"Huawei Technologies Co., Ltd."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"FusionSphere OpenStack V100R006C00SPC102(NFV)has an improper verification of cryptographic signature vulnerability. The software does not verify the cryptographic signature. An attacker with high privilege may exploit this vulnerability to inject malicious software."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"improper verification of cryptographic signature"}]}]},"references":{"reference_data":[{"name":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171018-01-fusionsphere-en","refsource":"CONFIRM","url":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171018-01-fusionsphere-en"}]}},"nvd":{"publishedDate":"2017-11-22 19:29:00","lastModifiedDate":"2017-12-08 19:04:00","problem_types":["CWE-347"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.7,"baseSeverity":"MEDIUM"},"exploitabilityScore":0.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:huawei:fusionsphere_openstack:v100r006c00spc102\\(nfv\\):*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"8190","Ordinal":"105085","Title":"CVE-2017-8190","CVE":"CVE-2017-8190","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"8190","Ordinal":"1","NoteData":"FusionSphere OpenStack V100R006C00SPC102(NFV)has an improper verification of cryptographic signature vulnerability. The software does not verify the cryptographic signature. An attacker with high privilege may exploit this vulnerability to inject malicious software.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"8190","Ordinal":"2","NoteData":"2017-11-22","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"8190","Ordinal":"3","NoteData":"2017-11-22","Type":"Other","Title":"Modified"}]}}}