PT-2020-15012 · Fnet · Fnet

Published

2020-12-11

·

Updated

2023-10-12

·

CVE-2020-17470

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions FNET versions through 4.6.4
Description An issue was discovered in the code that initializes the DNS client interface structure, where it does not set sufficiently random transaction IDs, always setting them to 1 in fnet dns poll in fnet dns.c. This significantly simplifies DNS cache poisoning attacks.
Recommendations For versions through 4.6.4, as a temporary workaround, consider implementing additional measures to prevent DNS cache poisoning attacks, such as restricting access to the DNS client interface or using external DNS security solutions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2020-17470

Affected Products

Fnet