CVE-2002-2213

Infoblox DNS One - DNS Cache Poisoning

Title source: llm
STIX 2.1

Description

The DNS resolver in unspecified versions of Infoblox DNS One, when resolving recursive DNS queries for arbitrary hosts, allows remote attackers to conduct DNS cache poisoning via a birthday attack that uses a large number of open queries for the same resource record (RR) combined with spoofed responses, which increases the possibility of successfully spoofing a response in a way that is more efficient than brute force methods.

References (4)

Core 4
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/457875
Third Party Advisory, US Government Resource x_refsource_confirm
http://www.kb.cert.org/vuls/id/IAFY-5FDPYJ

Scores

EPSS 0.0691
EPSS Percentile 91.5%

Details

Status published
Products (24)
infoblox/dns_one
isc/bind 4.9
isc/bind 4.9.2
isc/bind 4.9.3
isc/bind 4.9.4
isc/bind 4.9.5 (2 CPE variants)
isc/bind 4.9.6
isc/bind 4.9.7
isc/bind 4.9.8
isc/bind 4.9.9
... and 14 more
Published Dec 31, 2002
Tracked Since Feb 18, 2026