Skip to main content

Vendor/product archive

huawei / fusioncompute CVEs

Beta · best-effort

21 CVEs tagged to huawei / fusioncompute1 Critical, 10 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2020-9236

Published Dec 27, 2024

There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some operations properly. Attackers can exploit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9222

Published Dec 27, 2024

There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37102

Published Nov 23, 2021

There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command u…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37106

Published Sep 28, 2021

There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software construc…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37105

Published Sep 28, 2021

There is an improper file upload control vulnerability in FusionCompute 6.5.0, 6.5.1 and 8.0.0. Due to the improper verification of file to be uploaded and does not strictly restr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22358

Published May 27, 2021

There is an insufficient input validation vulnerability in FusionCompute 8.0.0. Due to the input validation is insufficient, an attacker can exploit this vulnerability to upload a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9114

Published Dec 1, 2020

FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9116

Published Dec 1, 2020

Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to exploit this vulnerability. D…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9128

Published Nov 12, 2020

FusionCompute versions 8.0.0 have an insecure encryption algorithm vulnerability. Attackers with high permissions can exploit this vulnerability to cause information leak.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9246

Published Aug 21, 2020

FusionCompute 8.0.0 has an information leak vulnerability. A module does not launch strict access control and information protection. Attackers with low privilege can get some ext…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9233

Published Aug 17, 2020

FusionCompute 8.0.0 have an insufficient authentication vulnerability. An attacker may exploit the vulnerability to delete some files and cause some services abnormal.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-9242

Published Aug 17, 2020

FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful exploit could allow an authen…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9229

Published Aug 14, 2020

FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, attackers may exploit this vulnerability to obtain certain…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9228

Published Aug 14, 2020

FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, attackers may exploit this vulnerability to obtain certain…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9078

Published Aug 10, 2020

FusionCompute 8.0.0 have local privilege escalation vulnerability. A local, authenticated attacker could perform specific operations to exploit this vulnerability. Successful expl…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9248

Published Jul 31, 2020

Huawei FusionComput 8.0.0 have an improper authorization vulnerability. A module does not verify some input correctly and authorizes files with incorrect access. Attackers can exp…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8158

Published Nov 22, 2017

FusionCompute V100R005C00 and V100R005C10 have an improper authorization vulnerability due to improper permission settings for a certain file on the host machine. An authenticated…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6827

Published Sep 26, 2016

Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4057

Published Jun 30, 2016

Huawei FusionCompute before V100R005C10SPC700 allows remote authenticated users to cause a denial of service (resource consumption) via a large number of crafted packets.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8336

Published Apr 14, 2016

Huawei FusionCompute with software before V100R005C10SPC700 allows remote authenticated users to obtain sensitive "role and permission" information via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1