Huawei FusionSphere OpenStack router Authentication Bypass Vulnerability (CVE-2017-8194)
Huawei FusionSphere OpenStack router Authentication Bypass Vulnerability (CVE-2017-8194)
Release date:
Updated on:
Affected Systems:
Huawei FusionSphere OpenStack 100R006C00SPC102 (NFV)
Description:
Bugtraq id: 102209
CVE (CAN) ID: CVE-2017-8194
FusionSphere is a cloud operating system with proprietary intellectual property rights of Huawei.
FusionSphere OpenStack V100R006C00SPC102 (NFV) has an identity authentication vulnerability. This vulnerability allows authenticated remote attackers to execute unauthorized operations by constructing rest messages.
<* Source: vendor
*>
Suggestion:
Vendor patch:
Huawei
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.huawei.com
Http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170830-02-OpenStack-en