CVE-2017-6520: Critical severity Bose Soundtouch 30 vulnerability
The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6520?
CVE-2017-6520 is rated as a potential denial of service vulnerability that could lead to traffic amplification.
How do I fix CVE-2017-6520?
To mitigate CVE-2017-6520, ensure that your Bose Soundtouch 30 firmware is updated to the latest version provided by the manufacturer.
What type of attack can exploit CVE-2017-6520?
CVE-2017-6520 can be exploited through a denial of service attack via UDP traffic amplification.
Is CVE-2017-6520 specific to any hardware?
Yes, CVE-2017-6520 specifically affects the Bose Soundtouch 30 device.
Can CVE-2017-6520 expose sensitive information?
Yes, CVE-2017-6520 may allow remote attackers to obtain potentially sensitive information through improper responses to unicast queries.