PT-2021-14937 · Huawei · Nfv Fusionsphere+3
Published
2021-02-06
·
Updated
2022-07-12
·
CVE-2021-22299
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ManageOne versions 6.5.0 through 8.0.RC3.SPC100
NFV FusionSphere versions 6.5.1.SPC23 through 8.0.0.SPC12
SMC2.0 versions V600R019C00 through V600R019C10
iMaster MAE-M version MAE-TOOL(FusionSphereBasicTemplate Euler X86)V100R020C10SPC220
Description:
A local privilege escalation issue exists in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this issue. Successful exploitation may cause the attacker to obtain a higher privilege.
Recommendations:
For ManageOne versions 6.5.0 through 8.0.RC3.SPC100, update to a version that is not affected by this issue.
For NFV FusionSphere versions 6.5.1.SPC23 through 8.0.0.SPC12, update to a version that is not affected by this issue.
For SMC2.0 versions V600R019C00 through V600R019C10, update to a version that is not affected by this issue.
For iMaster MAE-M version MAE-TOOL(FusionSphereBasicTemplate Euler X86)V100R020C10SPC220, update to a version that is not affected by this issue.
As a temporary workaround, consider restricting access to the affected products until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Manageone
Nfv Fusionsphere
Smc2.0
Imaster Mae-M