CVE-2017-10874

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
01/12/2017
Last modified:
20/04/2025

Description

PWR-Q200 does not use random values for source ports of DNS query packets, which allows remote attackers to conduct DNS cache poisoning attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ntt-east:pwr-q200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ntt-east:pwr-q200:-:*:*:*:*:*:*:*