SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1099

DNS rebinding vulnerability found in etcd 3.3.1 and earlier.

MEDIUM 5.5EPSS 0.50%

Does this matter?

Lower severity and a low EPSS score (0.50%). Track it; it rarely justifies an emergency change on its own.

Description

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

CVSS 3.0
5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.50% probability · 41th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
redhat/etcd · fedoraproject/fedora
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.