Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-27393

Опубликовано: 22 апр. 2021
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

A vulnerability has been identified in Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2013.08), Nucleus Source Code (Versions including affected DNS modules). The DNS client does not properly randomize UDP port numbers of DNS requests. That could allow an attacker to poison the DNS cache or spoof DNS resolving.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:siemens:nucleus_net:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:nucleus_readystart_v3:*:*:*:*:*:*:*:*
Версия до 2013.08 (исключая)
cpe:2.3:a:siemens:nucleus_source_code:-:*:*:*:*:*:*:*

EPSS

Процентиль: 44%
0.00218
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-330
CWE-330

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

A vulnerability has been identified in Nucleus NET (All versions), Nucleus RTOS (versions including affected DNS modules), Nucleus ReadyStart (All versions < V2013.08), Nucleus Source Code (versions including affected DNS modules), VSTAR (versions including affected DNS modules). The DNS client does not properly randomize UDP port numbers of DNS requests. That could allow an attacker to poison the DNS cache or spoof DNS resolving.

EPSS

Процентиль: 44%
0.00218
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-330
CWE-330