CVE-2019-6015
Summary
| CVE | CVE-2019-6015 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-04 19:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | FON2601E-SE, FON2601E-RE, FON2601E-FSW-S, and FON2601E-FSW-B with firmware versions 1.1.7 and earlier contain an issue where they may behave as open resolvers. If this vulnerability is exploited, FON routers may be leveraged for DNS amplification attacks to some other entities. |
Risk And Classification
Problem Types: CWE-400
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Fon | Fon2601e-fsw-b | - | All | All | All |
| Hardware | Fon | Fon2601e-fsw-b | - | All | All | All |
| Operating System | Fon | Fon2601e-fsw-b Firmware | All | All | All | All |
| Hardware | Fon | Fon2601e-fsw-s | - | All | All | All |
| Hardware | Fon | Fon2601e-fsw-s | - | All | All | All |
| Operating System | Fon | Fon2601e-fsw-s Firmware | All | All | All | All |
| Hardware | Fon | Fon2601e-re | - | All | All | All |
| Hardware | Fon | Fon2601e-re | - | All | All | All |
| Operating System | Fon | Fon2601e-re Firmware | All | All | All | All |
| Hardware | Fon | Fon2601e-se | - | All | All | All |
| Hardware | Fon | Fon2601e-se | - | All | All | All |
| Operating System | Fon | Fon2601e-se Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVNVU#94678942: FON routers may behave as an open resolver | MISC | jvn.jp | Third Party Advisory |
| Security check | MISC | fonjapan.zendesk.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.