ZeroHour

CVE-2022-34294

PoC
CVSS 3.1
9.8 critical
EPSS
2%p77
Published
()
Modified
Description

totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.

Vendors
totd project
Products
totd
Weakness
CWE-331
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.