Overview
Securifi Almond, firmware version AL1-R200-L302-W33 and earlier, and Securifi Almond 2015, firmware version AL2-R088 and earlier, contain multiple vulnerabilities.
Description
CWE-330: Use of Insufficiently Random Values - CVE-2015-2914 Securifi Almond and Almond 2015 use static source ports for all DNS queries originating from the local area network (LAN). Additionally, DNS queries originating from the Almond itself, such as those to resolve the name of the firmware update server, use predictable TXIDs that start at 0x0002 and increase incrementally. An attacker with the ability to spoof DNS responses can cause Almond LAN clients to contact incorrect or malicious hosts under the attacker's control. |
Impact
A remote, unauthenticated attacker may be able to spoof DNS responses to cause Almond LAN clients to contact attacker-controlled hosts or induce an authenticated user into making an unintentional request to the web server that will be treated as an authentic request. |
Solution
Apply an update |
Limit usage of web management |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Temporal | 5.8 | E:POC/RL:W/RC:C |
Environmental | 4.4 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://www.securifi.com/almond
- https://firmware.securifi.com/AL1/AL1-R201EXP10-L304-W34
- https://firmware.securifi.com/AL2/AL2-R088m
- https://cwe.mitre.org/data/definitions/330.html
- https://cwe.mitre.org/data/definitions/319.html
- https://cwe.mitre.org/data/definitions/255.html
- https://cwe.mitre.org/data/definitions/352.html
- https://cwe.mitre.org/data/definitions/20.html
Acknowledgements
These vulnerabilities were reported by Joel Land of the CERT/CC.
This document was written by Joel Land.
Other Information
CVE IDs: | CVE-2015-2914, CVE-2015-2915, CVE-2015-2916, CVE-2015-2917 |
Date Public: | 2015-09-10 |
Date First Published: | 2015-09-10 |
Date Last Updated: | 2015-09-15 13:16 UTC |
Document Revision: | 31 |