CVE-2016-8801 describes a command injection vulnerability in Huawei OceanStor 5600 V3 storage systems running firmware V300R003C00C10 and earlier. An attacker with administrator privileges can inject and execute arbitrary commands with root privileges. This vulnerability has a CVSS v3 score of 7.2 (HIGH), indicating a high impact on confidentiality, integrity, and availability, with low attack complexity. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in the KEV catalog, suggesting it is not actively exploited. Community discussion and media coverage are minimal, typical for the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= v300r003c00c10CPE matchmatch criteria | cpe:2.3:o:huawei:oceanstor_5600_v3_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.