CVE-2022-34294

CRITICAL

totd 1.5.3 - Insufficient Entropy in DNS Query Source Port

Title source: llm
STIX 2.1

Description

totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.

References (4)

Core 4
Core References
Technical Description, Third Party Advisory x_refsource_misc
https://www.usenix.org/conference/usenixsecurity22/presentation/jeitner
Exploit, Mailing List, Third Party Advisory x_refsource_misc
https://www.openwall.com/lists/oss-security/2022/08/14/2

Scores

CVSS v3 9.8
EPSS 0.0144
EPSS Percentile 69.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-331
Status published
Products (1)
totd_project/totd 1.5.3
Published Aug 15, 2022
Tracked Since Feb 18, 2026