Este site utiliza cookies. Ao continuar navegando no site, você concorda com esse uso. Leia nossa política de privacidade

Security Notice - Statement About the SQL Injection Vulnerability in Huawei Enterprise Proxy Servers Disclosed by WooYun

  • Initial Release Date: 2015-09-29
  • Last Release Date: 2015-09-29

Huawei has noticed that WooYun disclosed an SQL injection vulnerability in Huawei enterprise proxy servers and immediately launched an investigation.

The investigation shows that the vulnerability lies in the V400R001 version of the Enterprise Information Engine (EIE) product. This version has reached the End of Service (EOS) phase since June 30, 2014. Huawei has established a lifecycle management system and clarifies the product lifecycle strategy and product termination strategy, implementing lifecycle management in accordance with industry practices. Customers using this version are advised to process the system based on the EOS notice. 

2015-09-29 Final

Huawei adheres to protecting the ultimate interests of users with best efforts and the principle of responsible disclosure and deal with product security issues through our response mechanism. Please report to Huawei PSIRT at psirt@huawei.com if you find any security vulnerability of Huawei products.