CVE-2015-7282 Information

Description

ReadyNet WRT300N-DD devices with firmware 1.0.26 use the same source port number for every DNS query which makes it easier for remote attackers to spoof responses by selecting that number for the destination port.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Reference

http://www.securityfocus.com/bid/78814 https://www.kb.cert.org/vuls/id/167992

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

CHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

5.8

Share on: