Fusionsphere Openstack

Vendor:

First CVE: Nov 22, 2017 · Active for 8 years

22
Total CVEs
More Total CVEs than 94% of tracked products
7.3
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Fusionsphere Openstack over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 22, 2017
8 years ago
Most Recent CVE
Aug 11, 2020
2,173 days ago

CVE Severity & Scoring

Fusionsphere Openstack22 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local4 (18.2%)
Network8 (36.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network10 (45.5%)
Attack Complexity
Low20 (90.9%)
High2 (9.1%)
Unknown0 (0.0%)
User Interaction
None22 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (27.3%)
High4 (18.2%)
None12 (54.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authenticated, remote attacker may ex
Nov 22, 20178.828NONO
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An
Nov 22, 20178.828NONO
FusionSphere OpenStack 8.0.0 have a protection mechanism failure vulnerability. The product incorrectly uses a protection mechanism. An attacker has to find a way to exploit the vu
Aug 11, 20208.827NONO
The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authenticated, remote attacker may ex
Nov 22, 20178.826NONO
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An
Nov 22, 20178.825NONO
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An
Nov 22, 20178.825NONO
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An
Nov 22, 20178.825NONO
FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can
Nov 22, 20178.825NONO
FusionSphere OpenStack 6.5.1 have an improper permissions management vulnerability. The software does not correctly perform a privilege assignment when an actor attempts to perform
Jun 18, 20207.824NONO
There is an information leakage vulnerability on several Huawei products. Due to insufficient communication protection for specific services, a remote, unauthorized attacker can ex
Nov 27, 20187.524NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Fusionsphere Openstack

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
v100r006c10rc218.80.9%00
v100r006c1068.11.1%00
v100r006c00spc102\(nfv\)87.00.8%00
v100r006c000spc102_\(nfv\)13.70.6%00
v100r006c0088.21.0%00
8.0.018.80.4%00
6.5.117.80.2%00
100r006c0017.51.0%00