Huawei FusionAccess with software V100R005C10 and V100R005C20 could allow remote attackers with specific permission to inject a Lightweight Directory Access Protocol (LDAP) operation command into a specific input variable to obtain sensitive information from the database.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fusionaccess | Huawei | v100r005c10 (including) | v100r005c10 (including) |
Fusionaccess | Huawei | v100r005c20 (including) | v100r005c20 (including) |