CVE-2017-2719
Last modified
CVE-2017-2719 is a vulnerability of currently unknown severity. FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Fusionsphere Openstack | v100r006c00 |
| Huawei | Fusionsphere Openstack | v100r006c10rc2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-2719?
How severe is CVE-2017-2719?
How do I fix CVE-2017-2719?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-2713HUAWEI P9 smartphones with software versions earlier before …
- CVE-2017-2714The GaussDB in FusionSphere OpenStack V100R005C10SPC705 and …
- CVE-2017-2715The Files APP 7.1.1.309 and earlier versions in some Huawei …
- CVE-2017-2716The camerafs driver in Mate 9 Versions earlier than MHA-AL00…
- CVE-2017-2717honor 8 Pro with software Duke-L09C10B120 and earlier versio…
- CVE-2017-2718FusionSphere OpenStack with software V100R006C00 and V100R00…8.8
- CVE-2017-2720FusionSphere OpenStack V100R006C00 has an information exposu…
- CVE-2017-2721Some Huawei smart phones with software Berlin-L21C10B130,Ber…
- CVE-2017-2722DP300 V500R002C00,TE60 with software V100R001C01, V100R001C1…
- CVE-2017-2723The Files APP 7.1.1.308 and earlier versions in some Huawei …
- CVE-2017-2724Bastet in P10 Plus and P10 smart phones with software earlie…
- CVE-2017-2725Bastet in P10 Plus and P10 smart phones with software earlie…
Are you affected by CVE-2017-2719?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
