| |
Vulnerability CVE-2019-6015
Published: 2019-10-04
Description: |
FON2601E-SE, FON2601E-RE, FON2601E-FSW-S, and FON2601E-FSW-B with firmware versions 1.1.7 and earlier contain an issue where they may behave as open resolvers. If this vulnerability is exploited, FON routers may be leveraged for DNS amplification attacks to some other entities. |
Type:
CWE-20 (Improper Input Validation)
CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
7.8/10 |
6.9/10 |
10/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
None |
None |
Complete |
References: |
http://jvn.jp/en/vu/JVNVU94678942/index.html
https://fonjapan.zendesk.com/hc/ja/articles/360000558942
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|