HIGH
An issue was discovered in HCC embedded InterNiche 4.0.1
Published Aug 19, 2021
7.5
HIGHCVSS 3.1
EPSS 1.27%
Description
An issue was discovered in HCC embedded InterNiche 4.0.1. This vulnerability allows the attacker to predict a DNS query's source port in order to send forged DNS response packets that will be accepted as valid answers to the DNS client's requests (without sniffing the specific request). Data is predictable because it is based on the time of day, and has too few bits.
Affected products
No data.
- < 4.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-18141 Advisory
- https://www.forescout.com/blog/new-critical-operational-technology-vulnerabilities-found-on-nichestack/ x_refsource_MISCMitigationThird Party Advisory
- https://www.kb.cert.org/vuls/id/608209 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-18141 | Advisory | |
| https://www.forescout.com/blog/new-critical-operational-technology-vulnerabilities-found-on-nichestack/ | x_refsource_MISCMitigationThird Party Advisory | |
| https://www.kb.cert.org/vuls/id/608209 | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 19, 2021
Updated Aug 3, 2024
Reserved Apr 15, 2021
Link CVE-2021-31228
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data