VulnerabilityModified
CVE-2022-34294
This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.
CRITICAL 9.8EPSS 1.81%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-331
- Affected
- totd project/totd
- Source
- cve@mitre.org
References
- https://github.com/fwdillema/totdThird Party Advisory
- https://www.blackhat.com/presentations/bh-jp-08/bh-jp-08-Kaminsky/BlackHat-Japan-08-Kaminsky-DNS08-BlackOps.pdfThird Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/14/2Exploit, Mailing List, Third Party Advisory
- https://www.usenix.org/conference/usenixsecurity22/presentation/jeitnerTechnical Description, Third Party Advisory
- https://github.com/fwdillema/totdThird Party Advisory
- https://www.blackhat.com/presentations/bh-jp-08/bh-jp-08-Kaminsky/BlackHat-Japan-08-Kaminsky-DNS08-BlackOps.pdfThird Party Advisory
- https://www.openwall.com/lists/oss-security/2022/08/14/2Exploit, Mailing List, Third Party Advisory
- https://www.usenix.org/conference/usenixsecurity22/presentation/jeitnerTechnical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.