vendor:
RiS-11/RiS-22/RiS-33
by:
Todor Donev
8.8
CVSS
HIGH
Remote DNS Change
400
CWE
Product Name: RiS-11/RiS-22/RiS-33
Affected Version From: V5.07.52_es_FRI01
Affected Version To: V5.07.52_es_FRI01
Patch Exists: YES
Related CWE: N/A
CPE: a:secutech:ris-11/ris-22/ris-33
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
Secutech RiS-11/RiS-22/RiS-33 V5.07.52_es_FRI01 Remote DNS Change PoC
This vulnerability allows cybercriminals to modify systems' DNS settings, allowing them to perform malicious activities such as steering unknowing users to bad sites, replacing ads on legitimate sites, controlling and redirecting network traffic, and pushing additional malware. Systems with vulnerable systems or devices who try to access certain sites are instead redirected to possibly malicious sites.
Mitigation:
System administrators should ensure that all systems and devices are updated with the latest security patches and that all DNS settings are properly configured.