4.3
CVE-2015-7296
- EPSS 1.11%
- Veröffentlicht 21.09.2015 10:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M use a linear algorithm for selecting the ID value in the header of a DNS query performed on behalf of the device itself, which makes it easier for remote attackers to spoof responses by including this ID value, as demonstrated by a response containing the address of the firmware update server, a different vulnerability than CVE-2015-2914.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Securifi ≫ Almond Firmware Version <= al1-r201exp10-l304-w33
Securifi ≫ Almond-2015 Firmware Version <= al2-r088
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.11% | 0.778 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|