ZeroHour

CVE-2020-13529

PoC
CVSS 3.1
6.1 medium
EPSS
1%p71
Published
()
Modified
Description

An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.

Vendors
systemd projectfedoraprojectnetapp
Products
systemd, fedora, active iq unified manager, cloud backup
Weakness
CWE-290
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.