MEDIUM · 4.2

CVE-2017-8196

FusionSphere V100R006C00SPC102(NFV) has an incorrect authorization vulnerability. An authenticated attacker could execute commands that he/she should have had no permission to perform, thereby queryin...

Vulnerability Description

FusionSphere V100R006C00SPC102(NFV) has an incorrect authorization vulnerability. An authenticated attacker could execute commands that he/she should have had no permission to perform, thereby querying, modifying, and deleting certain service data and making the service unavailable.

CVSS Score

4.2

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
HuaweiFusionspherev100r006c00spc102\(nfv\)

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-8196?

CVE-2017-8196 is a vulnerability with a CVSS score of 4.2 (MEDIUM). FusionSphere V100R006C00SPC102(NFV) has an incorrect authorization vulnerability. An authenticated attacker could execute commands that he/she should have had no permission to perform, thereby queryin...

How severe is CVE-2017-8196?

CVE-2017-8196 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-8196?

Check the references section above for vendor advisories and patch information. Affected products include: Huawei Fusionsphere.