CVE-2015-8263: High severity netgear wnr1000 firmware vulnerability
Published Dec 27, 2015
·Updated
NETGEAR WNR1000v3 devices with firmware 1.0.2.68 use the same source port number for every DNS query, which makes it easier for remote attackers to spoof responses by selecting that number for the destination port.
Affected Software
2 affected components
Netgear Wnr1000v3 Firmware=1.0.2.68
Netgear WNR1000v3
Event History
Dec 27, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8263?
The severity of CVE-2015-8263 is considered medium due to the risk of DNS spoofing attacks.
2
How do I fix CVE-2015-8263?
To fix CVE-2015-8263, upgrade the NETGEAR WNR1000v3 firmware to a version that addresses this vulnerability.
3
Who is affected by CVE-2015-8263?
CVE-2015-8263 affects NETGEAR WNR1000v3 devices running firmware version 1.0.2.68.
4
What type of attack is possible with CVE-2015-8263?
CVE-2015-8263 allows remote attackers to spoof DNS responses due to predictable source port number usage.
5
What are the potential consequences of CVE-2015-8263?
The potential consequences of CVE-2015-8263 include unauthorized access to sensitive information or disruption of network services.