HCC embedded InterNiche におけるデータの信頼性についての不十分な検証に関する脆弱性
| Title |
HCC embedded InterNiche におけるデータの信頼性についての不十分な検証に関する脆弱性
|
| Summary |
HCC embedded InterNiche には、データの信頼性についての不十分な検証に関する脆弱性が存在します。
|
| Possible impacts |
情報を改ざんされる可能性があります。 |
| Solution |
ベンダ情報および参考情報を参照して適切な対策を実施してください。 |
| Publication Date |
Aug. 4, 2021, midnight |
| Registration Date |
Dec. 21, 2021, noon |
| Last Update |
Dec. 21, 2021, noon |
|
CVSS3.0 : 重要
|
| Score |
7.5
|
| Vector |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
|
CVSS2.0 : 警告
|
| Score |
5
|
| Vector |
AV:N/AC:L/Au:N/C:N/I:P/A:N |
Affected System
| HCC Embedded |
|
NicheStack 4.0.1
|
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
その他
Change Log
| No |
Changed Details |
Date of change |
| 1 |
[2021年12月21日] 掲載 |
Dec. 21, 2021, noon |
NVD Vulnerability Information
CVE-2021-31228
| Summary |
An issue was discovered in HCC embedded InterNiche 4.0.1. This vulnerability allows the attacker to predict a DNS query's source port in order to send forged DNS response packets that will be accepted as valid answers to the DNS client's requests (without sniffing the specific request). Data is predictable because it is based on the time of day, and has too few bits.
|
| Publication Date |
Aug. 19, 2021, 8:15 p.m. |
| Registration Date |
Aug. 20, 2021, 10 a.m. |
| Last Update |
Nov. 21, 2024, 3:05 p.m. |
Affected software configurations
| Configuration1 |
or higher |
or less |
more than |
less than |
| cpe:2.3:a:hcc-embedded:nichestack:*:*:*:*:*:*:*:* |
|
|
|
4.3 |
Related information, measures and tools
Common Vulnerabilities List