First published: Fri Dec 01 2017(Updated: )
PWR-Q200 does not use random values for source ports of DNS query packets, which allows remote attackers to conduct DNS cache poisoning attacks.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Ntt-east Pwr-q200 Firmware | ||
Ntt-east Pwr-q200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10874 is a vulnerability in the PWR-Q200 firmware that allows remote attackers to conduct DNS cache poisoning attacks.
CVE-2017-10874 has a severity score of 7.5, which is considered high.
Remote attackers can exploit CVE-2017-10874 by conducting DNS cache poisoning attacks.
The affected software for CVE-2017-10874 is the Ntt-east Pwr-q200 Firmware.
No, Ntt-east Pwr-q200 is not vulnerable to CVE-2017-10874.
To fix CVE-2017-10874, it is recommended to update the PWR-Q200 firmware to a version that uses random values for source ports of DNS query packets.