PT-2020-15012 · Fnet · Fnet
Published
2020-12-11
·
Updated
2023-10-12
·
CVE-2020-17470
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FNET versions through 4.6.4
Description
An issue was discovered in the code that initializes the DNS client interface structure, where it does not set sufficiently random transaction IDs, always setting them to 1 in
fnet dns poll in fnet dns.c. This significantly simplifies DNS cache poisoning attacks.Recommendations
For versions through 4.6.4, as a temporary workaround, consider implementing additional measures to prevent DNS cache poisoning attacks, such as restricting access to the DNS client interface or using external DNS security solutions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fnet