CVE-2015-6586
Last modified
CVE-2015-6586 is a vulnerability of currently unknown severity. The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote attackers to obtain sensitive information by leveraging failure to restrict processing of mDNS unicast queries to the link local network.. EPSS estimates a 1.31% chance of exploitation in the next 30 days.
Description
The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote attackers to obtain sensitive information by leveraging failure to restrict processing of mDNS unicast queries to the link local network.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Wlan Acu2 Firmware | <= v200r005c00 |
| Huawei | Wlan Acu2 Firmware | <= v200r005c10 |
| Huawei | Wlan Acu2 Firmware | <= v200r006c00 |
| Huawei | Wlan Ac6005 Firmware | <= v200r005c00 |
| Huawei | Wlan Ac6005 Firmware | <= v200r005c10 |
| Huawei | Wlan Ac6005 Firmware | <= v200r006c00 |
| Huawei | Wlan Ac6605 Firmware | <= v200r005c00 |
| Huawei | Wlan Ac6605 Firmware | <= v200r005c10 |
| Huawei | Wlan Ac6605 Firmware | <= v200r006c00 |
References
- http://www.securityfocus.com/bid/76684Third Party Advisory, VDB Entry
- http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-453516.htmMitigation, Vendor Advisory
- http://www.securityfocus.com/bid/76684Third Party Advisory, VDB Entry
- http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-453516.htmMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-6586?
How severe is CVE-2015-6586?
How do I fix CVE-2015-6586?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-6580Multiple unspecified vulnerabilities in Google V8 before 4.5…
- CVE-2015-6581Double free vulnerability in the opj_j2k_copy_default_tcp_an…
- CVE-2015-6582The decompose function in platform/transforms/Transformation…
- CVE-2015-6583Google Chrome before 45.0.2454.85 does not display a locatio…
- CVE-2015-6584Cross-site scripting (XSS) vulnerability in the DataTables p…
- CVE-2015-6585hwpapp.dll in Hangul Word Processor allows remote attackers …
- CVE-2015-6587The vlserver in OpenAFS before 1.6.13 allows remote authenti…
- CVE-2015-6588Cross-site scripting (XSS) vulnerability in login-fsp.html i…
- CVE-2015-6589Directory traversal vulnerability in Kaseya Virtual System A…8.8
- CVE-2015-6591Directory traversal vulnerability in application/templates/a…5.5
- CVE-2015-6592Huawei UAP2105 before V300R012C00SPC160(BootRom) does not re…
- CVE-2015-6593Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
Are you affected by CVE-2015-6586?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
