« List of all CVEs

CVE-2020-13529

Published: 5/10/2021 Last updated: 8/4/2024 Reserved: 5/26/2020

An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.

CNA assigner: talos (b86d76f8-0f8a-4a96-a78d-d8abfc7fc29b) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 6.1 Medium CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H

Opam packages affected (2)

conf-libudev ocaml-systemd

Products affected (1)

Product Vendor Version
Systemd n/a n/a

References (14)