vulnerability

Oracle Linux: CVE-2020-13529: ELSA-2021-4361: NetworkManager security, bug fix, and enhancement update (MODERATE) (Multiple Advisories)

Severity
5
CVSS
(AV:A/AC:H/Au:N/C:N/I:N/A:C)
Published
Apr 26, 2021
Added
Nov 17, 2021
Modified
Nov 29, 2024

Description

An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.
An exploitable denial of service vulnerability exists in systemd which does not fully implement RFC3203, as it does not support authentication of FORCERENEW packets. A specially crafted DHCP FORCERENEW packet can cause a system, running the DHCP client, to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHPACK packets to reconfigure the system with arbitrary network settings.

Solution(s)

oracle-linux-upgrade-networkmanageroracle-linux-upgrade-networkmanager-adsloracle-linux-upgrade-networkmanager-bluetoothoracle-linux-upgrade-networkmanager-cloud-setuporacle-linux-upgrade-networkmanager-config-connectivity-oracleoracle-linux-upgrade-networkmanager-config-serveroracle-linux-upgrade-networkmanager-dispatcher-routing-rulesoracle-linux-upgrade-networkmanager-libnmoracle-linux-upgrade-networkmanager-libnm-develoracle-linux-upgrade-networkmanager-ovsoracle-linux-upgrade-networkmanager-ppporacle-linux-upgrade-networkmanager-teamoracle-linux-upgrade-networkmanager-tuioracle-linux-upgrade-networkmanager-wifioracle-linux-upgrade-networkmanager-wwan
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.