This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
Huawei E5151 and E5186 allow DNS query packets using the static source port. Attackers can exploit the vulnerability to launch DNS Spoofing Attack and compromise the normal service of DNS. (Vulnerability ID: HWPSIRT-2015-10001)
This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2015-8265.
Huawei has released software update to fix this vulnerability. This advisory is available at the following link:
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160129-01-dns-en
Product Name |
Affected Version |
Resolved Product and Version |
E5186 |
V200R001B306D01C00 |
Upgrade to V200R001B310D01SP00C00 |
E5151[1] |
E5151s-2TCPU-V200R001B141D13SP00C1080 |
Upgrade to E5151s-2TCPU-V200R001B146D27SP00C00 |
NOTE: [1] E5151 is a carrier-branded product, and users can obtain the fixed version from their carriers.
Attackers can exploit the vulnerability to launch DNS Spoofing Attack and compromise the normal service of DNS.
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:P/A:N)
Temporal Score: 4.1 (E:F/RL:O/RC:C)
Prerequisite:
1 Attackers can access to the device.
Attacking procedure:
The device allows DNS query packets using the static source port. Attackers can exploit the vulnerability to launch DNS Spoofing Attack and compromise the normal service of DNS.
This vulnerability was reported to Huawei PSIRT by Joel Land of the CERT/CC. Huawei would like to thank Joel Land for working with us and coordinated vulnerability disclosure to protect our customers.
2016-02-06 V1.2 UPDATED Revised the CVSS vector.
2016-02-04 V1.1 UPDATED Revised the information of affected products.
2016-01-29 V1.0 INITIAL
None
To enjoy Huawei PSIRT services and obtain Huawei product vulnerability information, please visit http://www.huawei.com/en/psirt.
To report a security vulnerability in Huawei products and solutions, please send it to PSIRT@huawei.com. For details, please visit http://www.huawei.com/en/psirt/report-vulnerabilities.