CVE-2015-6586
Summary
| CVE | CVE-2015-6586 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-23 04:29:00 UTC |
| Updated | 2017-06-07 17:27:00 UTC |
| Description | The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote attackers to obtain sensitive information by leveraging failure to restrict processing of mDNS unicast queries to the link local network. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Wlan Ac6005 | - | All | All | All |
| Hardware | Huawei | Wlan Ac6005 | - | All | All | All |
| Operating System | Huawei | Wlan Ac6005 Firmware | All | All | All | All |
| Operating System | Huawei | Wlan Ac6005 Firmware | All | All | All | All |
| Operating System | Huawei | Wlan Ac6005 Firmware | All | All | All | All |
| Hardware | Huawei | Wlan Ac6605 | - | All | All | All |
| Hardware | Huawei | Wlan Ac6605 | - | All | All | All |
| Operating System | Huawei | Wlan Ac6605 Firmware | All | All | All | All |
| Operating System | Huawei | Wlan Ac6605 Firmware | All | All | All | All |
| Operating System | Huawei | Wlan Ac6605 Firmware | All | All | All | All |
| Hardware | Huawei | Wlan Acu2 | - | All | All | All |
| Hardware | Huawei | Wlan Acu2 | - | All | All | All |
| Operating System | Huawei | Wlan Acu2 Firmware | All | All | All | All |
| Operating System | Huawei | Wlan Acu2 Firmware | All | All | All | All |
| Operating System | Huawei | Wlan Acu2 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - mDNS Message Improper Handling Vulnerability in Huawei WLAN AC Products - Huawei PSIRT | CONFIRM | www1.huawei.com | Mitigation, Vendor Advisory |
| Huawei WLAN AC Products CVE-2015-6586 Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.