Huawei FusionAccess with software V100R005C10 and V100R005C20 could allow remote attackers with specific permission to inject a Lightweight Directory Access Protocol (LDAP) operation command into a specific input variable to obtain sensitive information from the database.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8779
Reference (s):
- BID:94620
- URL: http://www.securityfocus.com/bid/94620
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20161130-01-ldap-en