Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-7296

Опубликовано: 21 сент. 2015
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M use a linear algorithm for selecting the ID value in the header of a DNS query performed on behalf of the device itself, which makes it easier for remote attackers to spoof responses by including this ID value, as demonstrated by a response containing the address of the firmware update server, a different vulnerability than CVE-2015-2914.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:securifi:almond_firmware:*:*:*:*:*:*:*:*
Версия до al1-r201exp10-l304-w33 (включая)
cpe:2.3:h:securifi:almond:*:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:securifi:almond-2015_firmware:*:*:*:*:*:*:*:*
Версия до al2-r088 (включая)
cpe:2.3:h:securifi:almond-2015:*:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.00822
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M use a linear algorithm for selecting the ID value in the header of a DNS query performed on behalf of the device itself, which makes it easier for remote attackers to spoof responses by including this ID value, as demonstrated by a response containing the address of the firmware update server, a different vulnerability than CVE-2015-2914.

EPSS

Процентиль: 74%
0.00822
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other