CVE-2014-4883

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
28/11/2014
Last modified:
12/04/2025

Description

resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lwip_project:lwip:*:*:*:*:*:*:*:* 1.4.1 (including)