PT-2021-14937 · Huawei · Nfv Fusionsphere+3

Published

2021-02-06

·

Updated

2022-07-12

·

CVE-2021-22299

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ManageOne versions 6.5.0 through 8.0.RC3.SPC100 NFV FusionSphere versions 6.5.1.SPC23 through 8.0.0.SPC12 SMC2.0 versions V600R019C00 through V600R019C10 iMaster MAE-M version MAE-TOOL(FusionSphereBasicTemplate Euler X86)V100R020C10SPC220
Description: A local privilege escalation issue exists in some Huawei products. A local, authenticated attacker could craft specific commands to exploit this issue. Successful exploitation may cause the attacker to obtain a higher privilege.
Recommendations: For ManageOne versions 6.5.0 through 8.0.RC3.SPC100, update to a version that is not affected by this issue. For NFV FusionSphere versions 6.5.1.SPC23 through 8.0.0.SPC12, update to a version that is not affected by this issue. For SMC2.0 versions V600R019C00 through V600R019C10, update to a version that is not affected by this issue. For iMaster MAE-M version MAE-TOOL(FusionSphereBasicTemplate Euler X86)V100R020C10SPC220, update to a version that is not affected by this issue. As a temporary workaround, consider restricting access to the affected products until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-22299

Affected Products

Manageone
Nfv Fusionsphere
Smc2.0
Imaster Mae-M