Huawei OceanStor 5600 V3 with V300R003C00C10 and earlier versions allows attackers with administrator privilege to inject a command into a specific command's parameters, and run this injected command with root privilege.
References
Link | Resource |
---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161207-01-storage-en | Vendor Advisory |
http://www.securityfocus.com/bid/94832 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2017-04-02 13:59
Updated : 2017-04-05 09:16
NVD link : CVE-2016-8801
Mitre link : CVE-2016-8801
JSON object : View
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Products Affected
huawei
- oceanstor_5600_v3_firmware
- oceanstor_5600_v3