CVE-2015-8265
Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with software before V200R001B310D01SP00C00 allow DNS query packets using the static source port, which makes it easier for remote attackers to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.91%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with software before V200R001B310D01SP00C00 allow DNS query packets using the static source port, which makes it easier for remote attackers to spoof responses via unspecified vectors.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.91% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- huawei/e5151 firmware · huawei/e5186 firmware
- Source
- cret@cert.org
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160129-01-dns-enVendor Advisory
- http://www.securityfocus.com/bid/82246
- https://www.kb.cert.org/vuls/id/972224Third Party Advisory, US Government Resource
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160129-01-dns-enVendor Advisory
- http://www.securityfocus.com/bid/82246
- https://www.kb.cert.org/vuls/id/972224Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.