PT-2015-7304 · Huawei · Huawei Wlan Ac6005+3
Publicado
2015-09-09
·
Atualizado
2017-06-07
·
CVE-2015-6586
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Huawei WLAN AC6005 versions prior to V200R006C00SPC100
Huawei WLAN AC6605 versions prior to V200R006C00SPC100
Huawei WLAN ACU2 versions prior to V200R006C00SPC100
Description
The issue concerns the mDNS module in Huawei WLAN AC products, which fails to restrict processing of mDNS unicast queries to the link local network. This allows remote attackers to obtain sensitive information by sending mDNS unicast queries from outside the link local network, such as the WAN.
Recommendations
For Huawei WLAN AC6005 versions prior to V200R006C00SPC100, update to version V200R006C00SPC100 or later.
For Huawei WLAN AC6605 versions prior to V200R006C00SPC100, update to version V200R006C00SPC100 or later.
For Huawei WLAN ACU2 versions prior to V200R006C00SPC100, update to version V200R006C00SPC100 or later.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Huawei Vrp
Huawei Wlan Ac6005
Huawei Wlan Ac6605
Huawei Wlan Acu2