CVE-2004-0789
Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause…
Does this matter?
Lower severity and a low EPSS score (2.77%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite 2.2x before 2.2.3 and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (CPU and network bandwidth consumption) by triggering a communications loop via (a) DNS query packets with localhost as a spoofed source address, or (b) a response packet that triggers a response packet.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 2.77% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- delegate/delegate · dnrd/dnrd · don moore/mydns · maradns/maradns · pliant/pliant dns server · posadis/posadis · qbik/wingate · team johnlong/raidendnsd · axis/2100 network camera · axis/2110 network camera · axis/2120 network camera · axis/2400 video server · axis/2401 video server · axis/2420 network camera · axis/2460 network dvr
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/13145Patch
- http://securitytracker.com/id?1012157Patch
- http://www.niscc.gov.uk/niscc/docs/al-20041130-00862.html?lang=enVendor Advisory
- http://www.niscc.gov.uk/niscc/docs/re-20041109-00957.pdfVendor Advisory
- http://www.posadis.org/advisories/pos_adv_006.txtPatch, Vendor Advisory
- http://www.securityfocus.com/bid/11642Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17997
- http://secunia.com/advisories/13145Patch
- http://securitytracker.com/id?1012157Patch
- http://www.niscc.gov.uk/niscc/docs/al-20041130-00862.html?lang=enVendor Advisory
- http://www.niscc.gov.uk/niscc/docs/re-20041109-00957.pdfVendor Advisory
- http://www.posadis.org/advisories/pos_adv_006.txtPatch, Vendor Advisory
- http://www.securityfocus.com/bid/11642Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17997
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.