VulnerabilityModified
CVE-2022-33989
This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.
MEDIUM 5.3EPSS 1.00%
Does this matter?
Lower severity and a low EPSS score (1.00%). Track it; it rarely justifies an emergency change on its own.
Description
dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.00% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-331
- Affected
- dproxy-nexgen project/dproxy-nexgen
- Source
- cve@mitre.org
References
- https://sourceforge.net/projects/dproxy/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/14/3Exploit, Mailing List, Third Party Advisory
- https://www.usenix.org/conference/usenixsecurity22/presentation/jeitnerThird Party Advisory
- https://sourceforge.net/projects/dproxy/Third Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/14/3Exploit, Mailing List, Third Party Advisory
- https://www.usenix.org/conference/usenixsecurity22/presentation/jeitnerThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.