FusionSphere V100R006C00SPC102(NFV) has an incorrect authorization vulnerability. An authenticated attacker could execute commands that he/she should have had no permission to perform, thereby querying, modifying, and deleting certain service data and making the service unavailable.
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170913-01-fusionsphere-en