CVE-2017-8195
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authenticated, remote attacker may exploit the vulnerability to execute more operations by send a crafted rest message.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@huawei.com — http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170830-01-OpenStack-en
References
CWEs
CWE-287
Verify integrity in audit chain (admin only). AS-IS.