Published December 22, 2022
| Version v2
Report
Open
OID Takeover due to IANA's-PEN-Modification-Request Improper Access Control
Description
Ability of adversary to takeover entries of ICANN'S IANA's OID Registry due to improper authentication, authorization and access control.
There has been a Coordinated Vulnerability Disclosure attempt (CVD) with ICANN (and IANA), but there was no response.
Even though there have been, at least, two (2) attempts to register a Common Vulnerabilities and Exposures (CVE) Number by The Mitre Corporation (MITRE), there has been no meaningful response.
Notes
Files
E-mail Communications.pdf
Files
(2.4 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:2546ba9d5be740ea48fb1028d692bc35
|
919.6 kB | Preview Download |
|
md5:acb3d1b75afaeaf3ff9d98e8b11ea6a4
|
1.5 MB | Preview Download |