Vulnerabilities

Unpatched DNS bug affects millions of routers and IoT devices

0

A vulnerability in the domain name system (DNS) component of a popular C standard library which is present in a wide range of IoT products may put millions of devices at DNS poisoning attack risk.

It is possible for a threat actor to use DNS poisoning or DNS spoofing to redirect the victim to a malicious website hosted at an IP address on a server controlled by the attacker instead of the legitimate location.
The library uClibc and its fork from the OpenWRT team, uClibc-ng, both of which are widely used by major vendors like Netgear, Axis, and Linksys, as well as Linux distributions suitable for embedded applications.

According to researchers at Nozomi Networks, a patch is not yet available for the flaw which is now tracked as CVE-2022-05-02, from the developer of uClibc which makes products of up to 200 vendors at risk.

The uClibc library is a C standard library for embedded systems that offers various resources needed by functions and configuration modes on these devices.

The DNS implementation in that library provides a mechanism for performing DNS-related requests like lookups, translating domain names to IP addresses, etc.

Nozomi reviewed the trace of DNS requests performed by a connected device using the uClibc library and found some peculiarities caused by an internal lookup function. On further analysis it was found that DNS lookup request’s transaction ID was predictable. So, DNS poisoning might be possible under certain circumstances.

DNS poisoning is practically tricking the target device into pointing to an arbitrarily defined endpoint and engaging in network communications with it.

By doing that, the attacker would be able to reroute the traffic to a server under their direct control.

The flaw was discovered in September 2021 and informed CISA about it. They reported to the CERT Coordination Center in December and in January 2022, it disclosed the vulnerability to over 200 potentially impacted vendors.

Currently, all stakeholders are coordinating to develop a patch. First all the affected vendors will have to apply the patch by implementing the new uClibc version on firmware updates, so it will take a while for the fixes to reach end consumers.

Users of IoT and router devices must check for new firmware releases from vendors and apply the latest updates as soon as they are available

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Chinese cyber-espionage group targets Asian telecom sector

Previous article

Coca-Cola investigates data breach claims after ransomware attack

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *