Fusioncompute

Vendor:

First CVE: Apr 14, 2016 · Active for 10 years

21
Total CVEs
More Total CVEs than 94% of tracked products
4.2
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Fusioncompute over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2016
10 years ago
Most Recent CVE
Dec 27, 2024
576 days ago

CVE Severity & Scoring

Fusioncompute21 CVEs
All CVEs352,713 CVEs
MediumHighCritical
Attack Vector
Local8 (38.1%)
Network13 (61.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None21 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low13 (61.9%)
High5 (23.8%)
None3 (14.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
FusionCompute 8.0.0 have an insufficient authentication vulnerability. An attacker may exploit the vulnerability to delete some files and cause some services abnormal.
Aug 17, 20209.128NONO
There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command us
Nov 23, 20218.827NONO
FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful exploit could allow an authent
Aug 17, 20208.826NONO
There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some operations properly. Attackers can exploit
Dec 27, 20248.825NONO
FusionCompute 8.0.0 have local privilege escalation vulnerability. A local, authenticated attacker could perform specific operations to exploit this vulnerability. Successful explo
Aug 10, 20207.825NONO
There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software construct
Sep 28, 20217.224NONO
There is an improper file upload control vulnerability in FusionCompute 6.5.0, 6.5.1 and 8.0.0. Due to the improper verification of file to be uploaded and does not strictly restri
Sep 28, 20217.524NONO
FusionCompute 8.0.0 has an information disclosure vulnerability. Due to the properly protection of certain information, attackers may exploit this vulnerability to obtain certain i
Aug 14, 20207.524NONO
There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can
Dec 27, 20247.823NONO
FusionCompute versions 6.3.0, 6.3.1, 6.5.0, 6.5.1 and 8.0.0 have a privilege escalation vulnerability. Due to improper privilege management, an attacker with common privilege may a
Dec 1, 20207.823NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Fusioncompute

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
v100r005c1016.50.2%00
v100r005c0016.50.2%00
v100r003c1014.30.6%00
v100r003c0014.30.6%00
8.0.0167.20.6%00
6.5.167.40.5%00
6.5.057.80.6%00
6.3.147.90.5%00
6.3.047.90.5%00
6.0.018.80.9%00