DNS Resolver Vulnerability in uIP and lwIP Affecting Packet Security
CVE-2014-4883

Currently unrated

Key Information:

Status
Vendor
CVE Published:
28 November 2014

What is CVE-2014-4883?

The DNS resolver in uIP and lwIP prior to version 1.4.1 suffers from a significant security flaw where it fails to implement randomization for ID fields and source ports in DNS query packets. This weakness exposes the system to potential cache-poisoning attacks, allowing attackers to manipulate DNS responses by sending spoofed packets, thus undermining the integrity of the DNS resolution process.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.