Fusionsphere Openstack
Vendor:
First CVE: Nov 22, 2017 · Active for 8 years
22
Total CVEs
More Total CVEs than 94% of tracked products
7.3
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fusionsphere Openstack over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 22, 2017
8 years ago
Most Recent CVE
Aug 11, 2020
2,173 days ago
CVE Severity & Scoring
Fusionsphere Openstack22 CVEs
23%
73%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local4 (18.2%)
Network8 (36.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network10 (45.5%)
Attack Complexity
Low20 (90.9%)
High2 (9.1%)
Unknown0 (0.0%)
User Interaction
None22 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (27.3%)
High4 (18.2%)
None12 (54.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-8194HIGH The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authenticated, remote attacker may ex | Nov 22, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-8135HIGH The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An | Nov 22, 2017 | 8.8 | 28 | NO | NO |
CVE-2020-9079HIGH FusionSphere OpenStack 8.0.0 have a protection mechanism failure vulnerability. The product incorrectly uses a protection mechanism. An attacker has to find a way to exploit the vu | Aug 11, 2020 | 8.8 | 27 | NO | NO |
CVE-2017-8195HIGH The FusionSphere OpenStack V100R006C00SPC102(NFV) has an improper authentication vulnerability. Due to improper authentication on one port, an authenticated, remote attacker may ex | Nov 22, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-8134HIGH The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An | Nov 22, 2017 | 8.8 | 25 | NO | NO |
CVE-2017-8132HIGH The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An | Nov 22, 2017 | 8.8 | 25 | NO | NO |
CVE-2017-8131HIGH The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An | Nov 22, 2017 | 8.8 | 25 | NO | NO |
CVE-2017-2719HIGH FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can | Nov 22, 2017 | 8.8 | 25 | NO | NO |
CVE-2020-9225HIGH FusionSphere OpenStack 6.5.1 have an improper permissions management vulnerability. The software does not correctly perform a privilege assignment when an actor attempts to perform | Jun 18, 2020 | 7.8 | 24 | NO | NO |
CVE-2018-7977HIGH There is an information leakage vulnerability on several Huawei products. Due to insufficient communication protection for specific services, a remote, unauthorized attacker can ex | Nov 27, 2018 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Fusionsphere Openstack
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| v100r006c10rc2 | 1 | 8.8 | 0.9% | 0 | 0 |
| v100r006c10 | 6 | 8.1 | 1.1% | 0 | 0 |
| v100r006c00spc102\(nfv\) | 8 | 7.0 | 0.8% | 0 | 0 |
| v100r006c000spc102_\(nfv\) | 1 | 3.7 | 0.6% | 0 | 0 |
| v100r006c00 | 8 | 8.2 | 1.0% | 0 | 0 |
| 8.0.0 | 1 | 8.8 | 0.4% | 0 | 0 |
| 6.5.1 | 1 | 7.8 | 0.2% | 0 | 0 |
| 100r006c00 | 1 | 7.5 | 1.0% | 0 | 0 |