Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-37106

EPSS 0.53% · P67
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-37106

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands to the system.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Huawei FusionCompute 命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Huawei FusionCompute是中国华为(Huawei)公司的一个用于虚拟化支持的软件。该软件为虚拟引擎,为云端主机提供虚拟化支持。 Huawei FusionCompute产品CMA服务中存在命令注入漏洞。该漏洞源于未对特殊字符做有效过滤,攻击者可利用该漏洞在特定场景下处理证书文件时进行命令注入。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-FusionCompute 6.3.0,6.3.1,6.5.0,8.0.0 -

II. Public POCs for CVE-2021-37106

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-37106

登录查看更多情报信息。

Same Patch Batch · n/a · 2021-09-28 · 30 CVEs total

CVE-2021-29367IrfanView 缓冲区错误漏洞
CVE-2021-36165Ricon Industrial Cellular Router S9922L 安全漏洞
CVE-2021-37146OpenRobotics ros_comm 安全漏洞
CVE-2021-22535Directory And Resource Administrator 安全漏洞
CVE-2021-38124Micro Focus ArcSight Enterprise Security Manager 命令注入漏洞
CVE-2021-37104Huawei P40 代码问题漏洞
CVE-2021-37105Huawei FusionCompute 代码问题漏洞
CVE-2021-29358Irfanview缓冲区错误漏洞
CVE-2021-29360IrfanView 缓冲区错误漏洞
CVE-2021-29361IrfanView 缓冲区错误漏洞
CVE-2021-29362IrfanView 缓冲区错误漏洞
CVE-2021-29363IrfanView 缓冲区错误漏洞
CVE-2021-29364IrfanView 缓冲区错误漏洞
CVE-2021-29366IrfanView 缓冲区错误漏洞
CVE-2021-29365IrfanView 代码问题漏洞
CVE-2020-20125EARCLINK ESPCMS 跨站脚本漏洞
CVE-2021-36363Nagios XI 安全漏洞
CVE-2021-36364Nagios XI 安全漏洞
CVE-2021-36365Nagios XI 安全漏洞
CVE-2021-36366Nagios XI 安全漏洞

Showing top 20 of 30 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-37106

No comments yet


Leave a comment