Security Advisory

CVE-2021-37106

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-09-28 14:02:38
Last updated 2024-08-04 01:09:07
Assigner huawei
CVSS score not scored
State PUBLISHED

Description

There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system.