BlackKite: Home
Menu

PUBLISHED DATE: December 31, 2002CVE-2002-2212:
Spoofing Vulnerability

CVSS:
5
EPSS:
258.50%
Exploitability:
10
In KEV:
No
Description

The DNS resolver in unspecified versions of Fujitsu UXP/V, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.

Products
Questions to Ask Vendors
  1. Can you confirm whether your systems are affected by CVE-2002-2212, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2002-2212 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
References

Ready to get results you can trust?