4.3
CVSSv2

CVE-2014-4883

Published: 28/11/2014 Updated: 08/01/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and previous versions, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle malicious users to conduct cache-poisoning attacks via spoofed reply packets.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lwip project lwip