Jump to content

ARP Cache Poisoning attack detected since update to version 15.1.12.0


Recommended Posts

Hello,

 

I just updated ESET to the latest version 15.2.12.0 and since the reboot, I'm receiving Network alerts about ARP Cache Poisoning attacks been blocked. The source is my TV in the same network. 

Is this a false postive detection, bug in the latest version, or a real attack due to new added features and signatures? 

Anyone else having seen this? 

ARP1.PNG

ARP2.PNG

Link to comment
Share on other sites

Determine if the IP address assigned to the LG TV is a duplicate of any other device IP address within your local network.

Link to comment
Share on other sites

No it's not. But could the reason be, that the devices has both a Wifi connection and a cable connected to the network, this means the same device has 2 IP's but also 2 different MAC addresses, but that this is causing the above? 

I have both connected because the Wifi is not so stable, so I started having the TV cable connected as well.

Link to comment
Share on other sites

  • Administrators
39 minutes ago, Geraner said:

No it's not. But could the reason be, that the devices has both a Wifi connection and a cable connected to the network, this means the same device has 2 IP's but also 2 different MAC addresses, but that this is causing the above?

Yes, that should be it. There should be no difference in ARP cache poisoning detection between v15.1 and older versions.

Link to comment
Share on other sites

39 minutes ago, Geraner said:

this means the same device has 2 IP's but also 2 different MAC addresses

A physical device can only have one MAC address associated with it. You must be performing some type of MAC address spoofing activities which is what Eset ARP poisoning processing is detecting.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...