PT-2021-3981 · Hcc · Hcc Embedded Interniche
Published
2021-05-28
·
Updated
2022-07-12
·
CVE-2021-31228
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
HCC embedded InterNiche version 4.0.1
Description
The issue allows an attacker to predict a DNS query's source port, enabling them to send forged DNS response packets that will be accepted as valid answers to the DNS client's requests. This is possible because the data is predictable, based on the time of day, and has too few bits.
Recommendations
For HCC embedded InterNiche version 4.0.1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use of Insufficiently Random Values
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hcc Embedded Interniche