An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.
2021-05-10T16:15:07.373
2024-11-21T05:01:26.123
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:A/AC:M/Au:N/C:N/I:N/A:P
5.5
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | systemd_project | systemd | 245 | Yes |
Operating System | fedoraproject | fedora | 33 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Application | netapp | cloud_backup | - | Yes |