CVE-2014-4883
Last modified
CVE-2014-4883 is a vulnerability of currently unknown severity. resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lwip Project | Lwip | <= 1.4.1 |
References
- http://www.kb.cert.org/vuls/id/210620US Government Resource
- http://www.kb.cert.org/vuls/id/210620US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-4883?
How severe is CVE-2014-4883?
How do I fix CVE-2014-4883?
Are you affected by CVE-2014-4883?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
