CVE-2015-6586
Summary
| CVE | CVE-2015-6586 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-23 04:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote attackers to obtain sensitive information by leveraging failure to restrict processing of mDNS unicast queries to the link local network. |
Risk And Classification
Primary CVSS: v3.0 7.5 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-200 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Huawei | Wlan Ac6005 | - | All | All | All |
| Operating System | Huawei | Wlan Ac6005 Firmware | All | All | All | All |
| Operating System | Huawei | Wlan Ac6005 Firmware | All | All | All | All |
| Operating System | Huawei | Wlan Ac6005 Firmware | All | All | All | All |
| Hardware | Huawei | Wlan Ac6605 | - | All | All | All |
| Operating System | Huawei | Wlan Ac6605 Firmware | All | All | All | All |
| Operating System | Huawei | Wlan Ac6605 Firmware | All | All | All | All |
| Operating System | Huawei | Wlan Ac6605 Firmware | All | All | All | All |
| Hardware | Huawei | Wlan Acu2 | - | All | All | All |
| Operating System | Huawei | Wlan Acu2 Firmware | All | All | All | All |
| Operating System | Huawei | Wlan Acu2 Firmware | All | All | All | All |
| Operating System | Huawei | Wlan Acu2 Firmware | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory - mDNS Message Improper Handling Vulnerability in Huawei WLAN AC Products - Huawei PSIRT | af854a3a-2127-422b-91ae-364da2661108 | www1.huawei.com | Mitigation, Vendor Advisory |
| Huawei WLAN AC Products CVE-2015-6586 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.